-

CVE-2026-98060

bpf: Reject resilient lock operations in rbtree callbacks

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject resilient lock operations in rbtree callbacks

__bpf_rbtree_add() keeps parent and link pointers live across calls to the
program-supplied comparison callback. The verifier therefore requires the
root's lock to remain held throughout the callback.

The helper path enforces this rule for bpf_spin_lock() and
bpf_spin_unlock(), but the resilient lock kfunc argument path does not.
Since resilient locks may protect BPF rbtree roots, a callback can release
the root lock and let another CPU remove and free the node referenced by
the in-progress tree walk. The walk then resumes using freed pointers.

Reject resilient lock kfuncs in an rbtree comparison callback, matching
the existing policy for the spin lock helpers. Resilient-lock-protected
trees remain valid when their comparison callbacks leave lock state alone.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0de2046137f976e7302d43ac01d9894d07ac1fff
Version < cc2e065ed206aecd9b94564779244f3ffb26e356
Status affected
Version 0de2046137f976e7302d43ac01d9894d07ac1fff
Version < 71930202a0a0c49f0a3b45b41907a074cb780266
Status affected
Version 0de2046137f976e7302d43ac01d9894d07ac1fff
Version < 7b7b8b5960102566bd625ae829d1f330c5b5d104
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cc2e065ed206aecd9b94564779244f3ffb26e356
https://git.kernel.org/stable/c/71930202a0a0c49f0a3b45b41907a074cb780266
https://git.kernel.org/stable/c/7b7b8b5960102566bd625ae829d1f330c5b5d104