« Volver al listado

CVE-2026-98150

Estado: En análisisAlta (7)—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix BPF_F_CPU validation for sparse CPU IDs

BPF_F_CPU stores the target CPU ID in the upper 32 bits of the map operation flags. bpf_map_check_op_flags() currently compares that ID with num_possible_cpus(), which is the number of possible CPUs rather than a bound on CPU IDs.

On an arm64 QEMU guest with a CPU device-tree hole, the possible CPU mask was 0,2-3. A userspace program using raw bpf() syscalls creates a BPF_MAP_TYPE_PERCPU_ARRAY and performs update and lookup operations for each CPU by setting BPF_F_CPU and the CPU ID in the flags.

Leer descripción completaMostrar menos

With the old check, CPU 1 is incorrectly accepted while valid CPU 3 is rejected with -ERANGE. The CPU 1 update then reaches the per-CPU map access path and triggers:

Check the CPU ID against nr_cpu_ids and cpu_possible() instead. This rejects CPU IDs outside the valid range and CPUs absent from the possible mask, while allowing valid sparse CPU IDs.

Detalles técnicos trazas, registros y código del informe original
  Unable to handle kernel paging request at virtual address ...
  pc : __pi_memcpy_generic+0x5c/0x22c
  lr : bpf_percpu_array_update+0x2dc/0x2e8
  Call trace:
    __pi_memcpy_generic
    bpf_map_update_value
    map_update_elem
    __sys_bpf

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Fallo de validación en kernel Linux que permite escalada local (AV:L/PR:L) mediante manipulación de flags BPF para acceso a memoria percpu, causando pánico o corrupción de datos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98150",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2b421662c7887a0649fe409155a1f101562d0fa9",
              "lessThan": "bdc5941f6eeef90b76a07fd8ca38ac1933ba2195",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b421662c7887a0649fe409155a1f101562d0fa9",
              "lessThan": "ed54bf564ac52699cf4def3d0c2125d493e756f9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "include/linux/bpf.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/linux/bpf.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:46.580",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/bdc5941f6eeef90b76a07fd8ca38ac1933ba2195",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ed54bf564ac52699cf4def3d0c2125d493e756f9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix BPF_F_CPU validation for sparse CPU IDs\n\nBPF_F_CPU stores the target CPU ID in the upper 32 bits of the map\noperation flags. bpf_map_check_op_flags() currently compares that ID\nwith num_possible_cpus(), which is the number of possible CPUs rather\nthan a bound on CPU IDs.\n\nOn an arm64 QEMU guest with a CPU device-tree hole, the possible CPU\nmask was 0,2-3. A userspace program using raw bpf() syscalls creates\na BPF_MAP_TYPE_PERCPU_ARRAY and performs update and lookup operations\nfor each CPU by setting BPF_F_CPU and the CPU ID in the flags.\n\nWith the old check, CPU 1 is incorrectly accepted while valid CPU 3 is\nrejected with -ERANGE. The CPU 1 update then reaches the per-CPU map\naccess path and triggers:\n\n  Unable to handle kernel paging request at virtual address ...\n  pc : __pi_memcpy_generic+0x5c/0x22c\n  lr : bpf_percpu_array_update+0x2dc/0x2e8\n  Call trace:\n    __pi_memcpy_generic\n    bpf_map_update_value\n    map_update_elem\n    __sys_bpf\n\nCheck the CPU ID against nr_cpu_ids and cpu_possible() instead. This\nrejects CPU IDs outside the valid range and CPUs absent from the\npossible mask, while allowing valid sparse CPU IDs."
    }
  ],
  "lastModified": "2026-09-30T14:10:59.253",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}