« Volver al listado

CVE-2026-98075

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: reject BPF_PSEUDO_FUNC reference to the main program

fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real function addresses. This function is invoked from bpf_jit_subprogs() only when env->subprog_cnt > 1. Meaning that for any program like below:

The 'ptr' won't be ever converted to contain an address. In combination with e.g. bpf_timer_set_callback() this would lead to a function call at a bogus address.

Instead of complicating the implementation, just assume that no useful program needs main to be a sync or async callback and reject BPF_PSEUDO_FUNC loads for the main subprogram.

Detalles técnicos trazas, registros y código del informe original
  int main(void *ctx) {
    void *ptr = main;
    ...
    bpf_timer_set_callback(..., ptr);
    ...
  }

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98075",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "69c087ba6225b574afb6e505b72cb75242a3d844",
              "lessThan": "c74750dca96f40a1adb9d334f5a3152f44b270c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69c087ba6225b574afb6e505b72cb75242a3d844",
              "lessThan": "314c8caa9cb64ad60c5b969fe9a3e2dcdccf156f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69c087ba6225b574afb6e505b72cb75242a3d844",
              "lessThan": "8cb75f7ada25b1cf25f2f74dec3ba649b9064a09",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69c087ba6225b574afb6e505b72cb75242a3d844",
              "lessThan": "118212417ba0120d99f84154799f8880f07411f4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69c087ba6225b574afb6e505b72cb75242a3d844",
              "lessThan": "d6c39774ae093c9f7009cc4ae918f18fc1af7ae7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69c087ba6225b574afb6e505b72cb75242a3d844",
              "lessThan": "92f0bd0e2b632c6565ac2214a4d7d2ed37e5b9f6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "69c087ba6225b574afb6e505b72cb75242a3d844",
              "lessThan": "374b2c5561db80fcdd7cdce44af37a49416f61c7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:36.847",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/118212417ba0120d99f84154799f8880f07411f4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/314c8caa9cb64ad60c5b969fe9a3e2dcdccf156f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/374b2c5561db80fcdd7cdce44af37a49416f61c7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8cb75f7ada25b1cf25f2f74dec3ba649b9064a09",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/92f0bd0e2b632c6565ac2214a4d7d2ed37e5b9f6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c74750dca96f40a1adb9d334f5a3152f44b270c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d6c39774ae093c9f7009cc4ae918f18fc1af7ae7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: reject BPF_PSEUDO_FUNC reference to the main program\n\nfixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real\nfunction addresses. This function is invoked from bpf_jit_subprogs()\nonly when env->subprog_cnt > 1. Meaning that for any program like\nbelow:\n\n  int main(void *ctx) {\n    void *ptr = main;\n    ...\n    bpf_timer_set_callback(..., ptr);\n    ...\n  }\n\nThe 'ptr' won't be ever converted to contain an address.\nIn combination with e.g. bpf_timer_set_callback() this would lead to a\nfunction call at a bogus address.\n\nInstead of complicating the implementation, just assume that no useful\nprogram needs main to be a sync or async callback and reject\nBPF_PSEUDO_FUNC loads for the main subprogram."
    }
  ],
  "lastModified": "2026-10-03T11:18:28.910",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}