CVE-2026-98036
In the Linux kernel, the following vulnerability has been resolved:
bpf: Preserve special fields in recycled rhtab elements
rhtab_map_update_elem() initializes special fields after obtaining an element from bpf_mem_cache_alloc(). The allocator can return a fresh, zeroed unit, or recycle one from its RCU-pending lists before the registered destructor has run.
A BPF program can retain a map-value pointer after deleting its element and initialize and arm a timer through that pointer. If the deleted unit is recycled, check_and_init_map_value() clears the only pointer to the timer. Neither a later deletion nor rhtab_mem_dtor() can then cancel it, and the callback can run with its key and value pointing into freed memory.
Leer descripción completaMostrar menos
Do not reinitialize special fields on insertion. Fresh allocator units are already zeroed. For recycled units, the special fields are ownership state that must remain visible to the eventual destructor. copy_map_value() already skips those fields, matching the non-preallocated hash-map path and the lifecycle established by commit 275c30bcee66 ("bpf: Don't reinit map value in prealloc_lru_pop").
[ kkd: Split out the fix and rewrote the commit log ]
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.15%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98036",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6905f8601298ecd2d1932a4b4849bf265201118e",
"lessThan": "6a5266b8288216b86602ff687d528abfb066dfd8",
"versionType": "git"
},
{
"status": "affected",
"version": "6905f8601298ecd2d1932a4b4849bf265201118e",
"lessThan": "5df46ddcb7b36878c1b691e9057a0509042a2567",
"versionType": "git"
}
],
"programFiles": [
"kernel/bpf/hashtab.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"kernel/bpf/hashtab.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:32.340",
"references": [
{
"url": "https://git.kernel.org/stable/c/5df46ddcb7b36878c1b691e9057a0509042a2567",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6a5266b8288216b86602ff687d528abfb066dfd8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve special fields in recycled rhtab elements\n\nrhtab_map_update_elem() initializes special fields after obtaining an\nelement from bpf_mem_cache_alloc(). The allocator can return a fresh,\nzeroed unit, or recycle one from its RCU-pending lists before the\nregistered destructor has run.\n\nA BPF program can retain a map-value pointer after deleting its element\nand initialize and arm a timer through that pointer. If the deleted unit\nis recycled, check_and_init_map_value() clears the only pointer to the\ntimer. Neither a later deletion nor rhtab_mem_dtor() can then cancel it,\nand the callback can run with its key and value pointing into freed memory.\n\nDo not reinitialize special fields on insertion. Fresh allocator units are\nalready zeroed. For recycled units, the special fields are ownership state\nthat must remain visible to the eventual destructor. copy_map_value()\nalready skips those fields, matching the non-preallocated hash-map path and\nthe lifecycle established by commit 275c30bcee66 (\"bpf: Don't reinit map\nvalue in prealloc_lru_pop\").\n\n[ kkd: Split out the fix and rewrote the commit log ]"
}
],
"lastModified": "2026-09-25T11:17:32.340",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}