PT-2026-98748 · Linux · Linux

CVE-2026-98085

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: backtrack insn(): Handle ld {abs,ind} subprog exit edge
Nicholas Carlini reported a bug in precision backtracking mechanism for BPF LD | BPF {IND,ABS} instructions. These instructions are modelled as two branches:
  • fallthrough;
  • implicit exit from current subprogram.
The implicit exit case was not handled by the backtrack insn() function. When backtracking such a path backtrack insn() did not call bt subprog enter(), which meant that backtracking continued manipulating precision marks in a caller frame, while looking at instructions in a callee frame.
This lead to segmentation faults during verification (see the selftest), or unsound state pruning.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98085

Affected Products

Linux