« Volver al listado

CVE-2026-98039

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Require MEM_PERCPU for percpu kptr stores

map_kptr_match_type() treats perm_flags as the set of register type flags that a kptr field permits. Adding MEM_PERCPU to that set for BPF_KPTR_PERCPU does not require the source register to carry it, however. The subset test consequently accepts both a plain bpf_obj_new() allocation and a referenced kernel pointer into a __percpu_kptr map field.

Loads from the field are always marked MEM_PERCPU. Consumers then treat the stored value as the cookie returned by bpf_percpu_obj_new(): per-CPU pointer helpers relocate it, and map teardown selects the per-CPU free path. A plain allocation can therefore provide an arbitrary kernel read/write, while a kernel pointer can be relocated into an invalid address or sent through a missing destructor.

Leer descripción completaMostrar menos

Require the source MEM_PERCPU flag to match the destination field kind. This preserves valid bpf_percpu_obj_new() stores and rejects both the program-BTF and kernel-BTF variants.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98039",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "36d8bdf75a93190e5669b9d1d95994e13e15ba1d",
              "lessThan": "aaa9cf7707d1c5c0d2ca9d40c8b71652ac1c3c3f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d8bdf75a93190e5669b9d1d95994e13e15ba1d",
              "lessThan": "0bdd6121c8dd5f1764efe701ce26bb8e15acb172",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d8bdf75a93190e5669b9d1d95994e13e15ba1d",
              "lessThan": "ad4ebae5dbc2d47b544aa54f03c12490065be08a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "36d8bdf75a93190e5669b9d1d95994e13e15ba1d",
              "lessThan": "048029ba1c793f8cabc4ad5eea765da01903f8f1",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:32.663",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/048029ba1c793f8cabc4ad5eea765da01903f8f1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0bdd6121c8dd5f1764efe701ce26bb8e15acb172",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aaa9cf7707d1c5c0d2ca9d40c8b71652ac1c3c3f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ad4ebae5dbc2d47b544aa54f03c12490065be08a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Require MEM_PERCPU for percpu kptr stores\n\nmap_kptr_match_type() treats perm_flags as the set of register type flags\nthat a kptr field permits. Adding MEM_PERCPU to that set for\nBPF_KPTR_PERCPU does not require the source register to carry it, however.\nThe subset test consequently accepts both a plain bpf_obj_new() allocation\nand a referenced kernel pointer into a __percpu_kptr map field.\n\nLoads from the field are always marked MEM_PERCPU. Consumers then treat the\nstored value as the cookie returned by bpf_percpu_obj_new(): per-CPU pointer\nhelpers relocate it, and map teardown selects the per-CPU free path. A plain\nallocation can therefore provide an arbitrary kernel read/write, while a\nkernel pointer can be relocated into an invalid address or sent through a\nmissing destructor.\n\nRequire the source MEM_PERCPU flag to match the destination field kind.\nThis preserves valid bpf_percpu_obj_new() stores and rejects both the\nprogram-BTF and kernel-BTF variants."
    }
  ],
  "lastModified": "2026-09-25T11:17:32.663",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}