« Volver al listado

CVE-2026-98048

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: don't rewrite bpf_fastcall patterns entered by a jump

mark_fastcall_pattern_for_call() must ensure that matched "spill; call; fill" instruction series is not interrupted by a jump. Otherwise the rewrite applied by bpf_remove_fastcall_spills_fills() is not sound.

Record the instructions targeted by jumps in insn_aux_data[*].jump_target when the CFG is built and use this flag to stop growing a pattern at such an instruction. Jumps to the first spill are fine.

Note that existing insn_aux_data[*].jmp_point field can't be reused, as it marks subprogram return instructions.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98048",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5b5f51bff1b66cedb62b5ba74a1878341204e057",
              "lessThan": "24adbc2c3bbe3385ce922587e1f8e837a68b3e25",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5b5f51bff1b66cedb62b5ba74a1878341204e057",
              "lessThan": "0b1c83dc3c4401cd7e846548f62e3caf3d06742e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "include/linux/bpf_verifier.h",
            "kernel/bpf/cfg.c",
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/linux/bpf_verifier.h",
            "kernel/bpf/cfg.c",
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:33.663",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0b1c83dc3c4401cd7e846548f62e3caf3d06742e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/24adbc2c3bbe3385ce922587e1f8e837a68b3e25",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: don't rewrite bpf_fastcall patterns entered by a jump\n\nmark_fastcall_pattern_for_call() must ensure that matched\n\"spill; call; fill\" instruction series is not interrupted by a jump.\nOtherwise the rewrite applied by bpf_remove_fastcall_spills_fills()\nis not sound.\n\nRecord the instructions targeted by jumps in\ninsn_aux_data[*].jump_target when the CFG is built and use this flag\nto stop growing a pattern at such an instruction. Jumps to the first\nspill are fine.\n\nNote that existing insn_aux_data[*].jmp_point field can't be reused,\nas it marks subprogram return instructions."
    }
  ],
  "lastModified": "2026-09-25T11:17:33.663",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}