PT-2026-98813 · Linux · Linux Kernel
CVE-2026-98151
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the BPF (Berkeley Packet Filter) subsystem where a register invariants violation occurs during speculative pointer arithmetic. When processing instructions in
adjust ptr min max vals(), the mark reg32 unbounded() function sets the 32-bit register r32 to a full range before reg bounds sync() can re-derive it from the offset. If sanitize ptr alu() is called on an unprivileged path, it snapshots the register state via sanitize speculative path() and push stack() before the synchronization occurs. This results in an inconsistent state where var off and the 32-bit range are out of sync, triggering a verifier warning in reg bounds sanity check() when the speculative path is verified.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel