« Volver al listado

CVE-2026-98007

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject non-scalar bpf_loop iteration counts

bpf_loop() declares its nr_loops argument as ARG_ANYTHING. Privileged programs may pass pointer values to such arguments, so check_func_arg() lets a pointer-valued R1 reach the helper-specific checks.

Since commit bb124da69c47 ("bpf: keep track of max number of bpf_loop callback iterations"), the verifier marks R1 precise and reads its upper bound to limit callback simulation. Precision backtracking only accepts scalar registers, so passing a pointer instead triggers the "backtracking misuse" verifier warning. Kernels with panic_on_warn enabled subsequently panic.

Leer descripción completaMostrar menos

Introduce ARG_SCALAR for helper arguments that only accept scalar values and use it for bpf_loop() nr_loops. Generic helper argument validation then rejects pointers before loop inlining and precision processing.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98007",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bfc5c19b4b48840627af0d0f1c8f4461b276e508",
              "lessThan": "2ff38b3552af53238aee6c877ae64cc798d46fce",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bb124da69c47dd98d69361ec13244ece50bec63e",
              "lessThan": "656d40d1ca228ee21a9b3280432479fc9eae75ab",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bb124da69c47dd98d69361ec13244ece50bec63e",
              "lessThan": "e2e1161e03fecff6d2229a81b024337144bfcd97",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bb124da69c47dd98d69361ec13244ece50bec63e",
              "lessThan": "f8ae8275c721334ee50fafdd986fb83294eb941a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bb124da69c47dd98d69361ec13244ece50bec63e",
              "lessThan": "c3fd8e5fd100f122bad503bdc0e9277219533253",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.15",
              "lessThan": "6.6.158",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "include/linux/bpf.h",
            "kernel/bpf/bpf_iter.c",
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/linux/bpf.h",
            "kernel/bpf/bpf_iter.c",
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:28.967",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2ff38b3552af53238aee6c877ae64cc798d46fce",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/656d40d1ca228ee21a9b3280432479fc9eae75ab",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3fd8e5fd100f122bad503bdc0e9277219533253",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e2e1161e03fecff6d2229a81b024337144bfcd97",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f8ae8275c721334ee50fafdd986fb83294eb941a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject non-scalar bpf_loop iteration counts\n\nbpf_loop() declares its nr_loops argument as ARG_ANYTHING. Privileged\nprograms may pass pointer values to such arguments, so check_func_arg()\nlets a pointer-valued R1 reach the helper-specific checks.\n\nSince commit bb124da69c47 (\"bpf: keep track of max number of bpf_loop\ncallback iterations\"), the verifier marks R1 precise and reads its upper\nbound to limit callback simulation. Precision backtracking only accepts\nscalar registers, so passing a pointer instead triggers the \"backtracking\nmisuse\" verifier warning. Kernels with panic_on_warn enabled subsequently\npanic.\n\nIntroduce ARG_SCALAR for helper arguments that only accept scalar values\nand use it for bpf_loop() nr_loops. Generic helper argument validation then\nrejects pointers before loop inlining and precision processing."
    }
  ],
  "lastModified": "2026-10-03T11:18:23.630",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}