PT-2026-98748 · Linux · Linux
CVE-2026-98085
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: backtrack insn(): Handle ld {abs,ind} subprog exit edge
Nicholas Carlini reported a bug in precision backtracking mechanism
for BPF LD | BPF {IND,ABS} instructions. These instructions are
modelled as two branches:
- fallthrough;
- implicit exit from current subprogram.
The implicit exit case was not handled by the backtrack insn()
function. When backtracking such a path backtrack insn() did not
call bt subprog enter(), which meant that backtracking continued
manipulating precision marks in a caller frame, while looking at
instructions in a callee frame.
This lead to segmentation faults during verification (see the
selftest), or unsound state pruning.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux