CVE-2026-98019
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: mark a NULL call argument precise
check_func_arg() allows bpf_register_is_null() for nullable arguments w/o marking the underlying scalar register precise. Hence a checkpoint created on such a path would prune against arbitrary scalar value.
check_helper_call() enforces second parameter of the bpf_get_local_storage() to be zero, w/o marking the underlying scalar register precise. Hence a checkpoint created on such a path would prune against arbitrary scalar value.
Grouping these two into one patch, as they share the same fixes tag.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b5dc0163d8fd78e64a7e21f309cf932fda34353e < 69a9ad004ccf5d45e534c7d503f47f643abe64b7 | affected |
| Linux | Linux | b5dc0163d8fd78e64a7e21f309cf932fda34353e < 1a3a10b030c96ea88868ccc060a16827c01eaa5a | affected |
| Linux | Linux | 5.3 | affected |
| Linux | Linux | 0 < 5.3 | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/69a9ad004ccf5d45e534c7d503f47f643abe64b7
- https://git.kernel.org/stable/c/1a3a10b030c96ea88868ccc060a16827c01eaa5a
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.