CVE-2026-98034
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Mark NULL kptr stores precise
check_map_kptr_access() permits a scalar store into an untrusted kptr field only when the register is known to contain zero. Unlike other verifier checks whose outcome depends on a scalar value, it does not mark that register precise.
A state checkpoint reached with an imprecise zero can therefore prune a second path that reaches the store with an arbitrary nonzero scalar. The program can write attacker-controlled bits into the kptr field and load them back as a PTR_TO_BTF_ID.
Call mark_chain_precision() before accepting a known-zero register. This forces state equivalence to compare its scalar range and makes the verifier visit and reject a path carrying a nonzero value.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 61df10c7799e27807ad5e459eec9d77cddf8bf45 < 86168208737bdd267d92d855d453d1d2f840df19 | affected |
| Linux | Linux | 61df10c7799e27807ad5e459eec9d77cddf8bf45 < ecdc5043794c9184aa8e6c814603899479c46b35 | affected |
| Linux | Linux | b5a8069835e5236824a84281592d29f859b33153 | affected |
| Linux | Linux | 5.18.18 < 5.19 | affected |
| Linux | Linux | 5.19 | affected |
| Linux | Linux | 0 < 5.19 | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/86168208737bdd267d92d855d453d1d2f840df19
- https://git.kernel.org/stable/c/ecdc5043794c9184aa8e6c814603899479c46b35
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.