PT-2026-98712 · Linux · Linux
CVE-2026-98049
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: zero extend the result of an arena 32-bit cmpxchg
bpf convert ctx accesses() rewrites an atomic on an arena pointer from
BPF STX | BPF ATOMIC to BPF STX | BPF PROBE ATOMIC, and it runs before
bpf opt subreg zext lo32 rnd hi32().
That pass emits an explicit zero extension for a 32-bit cmpxchg even
when bpf jit needs zext() is false. This is done because on some
architectures 32-bit cmpxchg requires explicit zero extension for the
dst register. E.g. on x86-64 'lock cmpxchg' does not change the %eax
if comparison is successful, while BPF semantics declare that each
operation on a 32-bit register zero extends it's upper half.
is cmpxchg insn() matches BPF MODE == BPF ATOMIC only, so an arena
cmpxchg misses said zero extension adjustment. This patch adjusts
is cmpxchg insn() to match BPF PROBE ATOMIC alongside BPF ATOMIC.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux