PT-2026-98811 · Linux · Linux Kernel

CVE-2026-98149

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF (Berkeley Packet Filter) subsystem regarding per-CPU map updates for array, hash, and cgroup storage maps when BPF F CPU or BPF F ALL CPUS are not used. The system uses a value buffer where per-CPU slots are packed based on possible-CPU order. However, the update paths incorrectly use the logical CPU ID to calculate the source offset via the formula value + size * cpu. This logic fails when possible CPU IDs are sparse (non-contiguous), leading to incorrect per-CPU values and an out-of-bounds read from the update buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98149

Affected Products

Linux Kernel