PT-2026-98813 · Linux · Linux Kernel

CVE-2026-98151

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF (Berkeley Packet Filter) subsystem where a register invariants violation occurs during speculative pointer arithmetic. When processing instructions in adjust ptr min max vals(), the mark reg32 unbounded() function sets the 32-bit register r32 to a full range before reg bounds sync() can re-derive it from the offset. If sanitize ptr alu() is called on an unprivileged path, it snapshots the register state via sanitize speculative path() and push stack() before the synchronization occurs. This results in an inconsistent state where var off and the 32-bit range are out of sync, triggering a verifier warning in reg bounds sanity check() when the speculative path is verified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98151

Affected Products

Linux Kernel