PT-2026-98724 · Linux · Linux

CVE-2026-98061

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject tail calls directly from callback frames
A tail call from a non-zero frame is modeled as a return from that frame. The verifier makes R0 unknown and calls prepare func exit() for the taken branch.
When the current frame is a synchronous callback, prepare func exit() enforces the callback return-value contract and marks R0 precise. Since the tail-call path synthesized R0 rather than deriving it from an instruction, precision backtracking reaches the callback-calling instruction with R0 still requested and triggers the "callback unexpected regs" verifier bug. A CAP BPF task can therefore cause a WARN and an -EFAULT BPF PROG LOAD.
Tail calls reachable from callbacks are already rejected later by check max stack depth(). Reject a tail call made directly by a callback before constructing the inconsistent return state, using the existing diagnostic. Tail calls from ordinary subprograms keep their current behavior.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98061

Affected Products

Linux