« Volver al listado

CVE-2026-98042

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Don't resurrect a scalar id dropped by collect_linked_regs()

check_cond_jmp_op() copies the compared registers into env->{false,true}_reg{1,2} before collect_linked_regs() runs and copies those snapshots back into both branch states afterwards.

collect_linked_regs() records at most LINKED_REGS_MAX members of a linked registers group in the jump history and calls clear_scalar_id() for every member that does not fit. The compared register is not exempt from that.

As a consequence, sync_linked_regs() might adjust ranges for more registers than bpf_bt_sync_linked_regs() can propagate precision to.

Leer descripción completaMostrar menos

Collect the linked registers before the snapshots are taken instead. This might lead to some unnecessary clear_scalar_id's, but from previous testing situations with many linked registers are extremely rare.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98042",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ec1d77cb0ee98249142dcd0376d76e7a48ba0b31",
              "lessThan": "e821ff19b8ef08255ff8d8234774ed814637e9bf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ec1d77cb0ee98249142dcd0376d76e7a48ba0b31",
              "lessThan": "73a98f96811e2cb0f4210b1caa8cb322f92f2a2b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:32.987",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/73a98f96811e2cb0f4210b1caa8cb322f92f2a2b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e821ff19b8ef08255ff8d8234774ed814637e9bf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Don't resurrect a scalar id dropped by collect_linked_regs()\n\ncheck_cond_jmp_op() copies the compared registers into\nenv->{false,true}_reg{1,2} before collect_linked_regs() runs and copies\nthose snapshots back into both branch states afterwards.\n\ncollect_linked_regs() records at most LINKED_REGS_MAX members of a\nlinked registers group in the jump history and calls clear_scalar_id()\nfor every member that does not fit. The compared register is not exempt\nfrom that.\n\nAs a consequence, sync_linked_regs() might adjust ranges for more\nregisters than bpf_bt_sync_linked_regs() can propagate precision to.\n\nCollect the linked registers before the snapshots are taken instead.\nThis might lead to some unnecessary clear_scalar_id's, but from\nprevious testing situations with many linked registers are\nextremely rare."
    }
  ],
  "lastModified": "2026-09-25T11:17:32.987",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}