PT-2026-98747 · Linux · Linux
CVE-2026-98084
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks
When processing calls to bpf loop() verifier marks R1 (and R4) as
precise. R1 tracks loop iterations number and because of the
'callback depth < R1' mechanics in check helper call() must be marked
precise. However, precision propagation for R1 was broken,
when bpf loop() call was verified on a second iteration.
Consider the following verification trace:
- main: bpf loop(nr loops, callback ...)
- callback: BPF EXIT
- main: bpf loop(nr loops, callback ...)
- ...
While the first visit of the call to bpf loop() propagated R1
precision as expected, the second call to mark chain precision() in
the check helper call() set R1, but it was immediately reset when
backtrack insn() processed preceding BPF EXIT in the loop deleted in
this patch.
Because of that, the second visit of the call to bpf loop() injected
checkpoint with R1 not marked as precise. Which could trick the
verifier into accepting unsafe programs. See the next patch for an
example of such program.
Commit is structured in a way to minimize conflicts when
'bpf' would be eventually merged with 'bpf-next'.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux