« Volver al listado

CVE-2026-98040

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Mark the zero register precise for a register-form NULL check

check_cond_jmp_op() accepts "if rA <op> rB" as a NULL check for a nullable pointer rA when rB is a scalar known to be zero, lifts PTR_MAYBE_NULL from rA in the corresponding branch and does not mark rB precise. Consider the following program:

The r6 == 0 path is explored first and the dereference is accepted. The r6 == 1 path is pruned at the checkpoint recorded for (1), so the comparison is never verified with a non-zero r6. At runtime a failed lookup returns NULL, NULL != 1 takes the non-NULL edge and the program dereferences a pointer that is zero.

Detalles técnicos trazas, registros y código del informe original
  r0 = bpf_get_prandom_u32();
  r6 = 1;                  /* the r6 == 0 path is explored first */
  if (r0 == 0) goto 1f;
  r6 = 0;
1:
  r0 = bpf_map_lookup_elem(map, &0);  /* absent, NULL at runtime */
  if (r0 == r6) goto 2f;   /* taken as a NULL check for r0       */
  *(u8 *)(r0 + 0);         /* verifier: map value; runtime: zero */
2:
  return 0;

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98040",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2f4cb53eed448c1aeb6f4b40cf9c810716d8218c",
              "lessThan": "ddca9a3b8833168dda3e62676648a636fb3f221c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2f4cb53eed448c1aeb6f4b40cf9c810716d8218c",
              "lessThan": "6aed0134d3cda6382385a734ae0158eb7df6b142",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:32.773",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6aed0134d3cda6382385a734ae0158eb7df6b142",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ddca9a3b8833168dda3e62676648a636fb3f221c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mark the zero register precise for a register-form NULL check\n\ncheck_cond_jmp_op() accepts \"if rA <op> rB\" as a NULL check for a\nnullable pointer rA when rB is a scalar known to be zero,\nlifts PTR_MAYBE_NULL from rA in the corresponding branch and does not\nmark rB precise. Consider the following program:\n\n  r0 = bpf_get_prandom_u32();\n  r6 = 1;                  /* the r6 == 0 path is explored first */\n  if (r0 == 0) goto 1f;\n  r6 = 0;\n1:\n  r0 = bpf_map_lookup_elem(map, &0);  /* absent, NULL at runtime */\n  if (r0 == r6) goto 2f;   /* taken as a NULL check for r0       */\n  *(u8 *)(r0 + 0);         /* verifier: map value; runtime: zero */\n2:\n  return 0;\n\nThe r6 == 0 path is explored first and the dereference is accepted.\nThe r6 == 1 path is pruned at the checkpoint recorded for (1),\nso the comparison is never verified with a non-zero r6. At runtime a\nfailed lookup returns NULL, NULL != 1 takes the non-NULL edge and the\nprogram dereferences a pointer that is zero."
    }
  ],
  "lastModified": "2026-09-25T11:17:32.773",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}