CVE-2026-98007

Summary

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject non-scalar bpf_loop iteration counts

bpf_loop() declares its nr_loops argument as ARG_ANYTHING. Privileged programs may pass pointer values to such arguments, so check_func_arg() lets a pointer-valued R1 reach the helper-specific checks.

Since commit bb124da69c47 ("bpf: keep track of max number of bpf_loop callback iterations"), the verifier marks R1 precise and reads its upper bound to limit callback simulation. Precision backtracking only accepts scalar registers, so passing a pointer instead triggers the "backtracking misuse" verifier warning. Kernels with panic_on_warn enabled subsequently panic.

Introduce ARG_SCALAR for helper arguments that only accept scalar values and use it for bpf_loop() nr_loops. Generic helper argument validation then rejects pointers before loop inlining and precision processing.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxbb124da69c47dd98d69361ec13244ece50bec63e < 656d40d1ca228ee21a9b3280432479fc9eae75abaffected
LinuxLinuxbb124da69c47dd98d69361ec13244ece50bec63e < e2e1161e03fecff6d2229a81b024337144bfcd97affected
LinuxLinuxbb124da69c47dd98d69361ec13244ece50bec63e < f8ae8275c721334ee50fafdd986fb83294eb941aaffected
LinuxLinuxbb124da69c47dd98d69361ec13244ece50bec63e < c3fd8e5fd100f122bad503bdc0e9277219533253affected
LinuxLinuxbfc5c19b4b48840627af0d0f1c8f4461b276e508affected
LinuxLinux6.6.15 < 6.7affected
LinuxLinux6.7affected
LinuxLinux0 < 6.7unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc2 <= *unaffected

Weaknesses

References