-

CVE-2026-98061

bpf: Reject tail calls directly from callback frames

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject tail calls directly from callback frames

A tail call from a non-zero frame is modeled as a return from that frame.
The verifier makes R0 unknown and calls prepare_func_exit() for the taken
branch.

When the current frame is a synchronous callback, prepare_func_exit()
enforces the callback return-value contract and marks R0 precise. Since the
tail-call path synthesized R0 rather than deriving it from an instruction,
precision backtracking reaches the callback-calling instruction with R0
still requested and triggers the "callback unexpected regs" verifier bug.
A CAP_BPF task can therefore cause a WARN and an -EFAULT BPF_PROG_LOAD.

Tail calls reachable from callbacks are already rejected later by
check_max_stack_depth(). Reject a tail call made directly by a callback
before constructing the inconsistent return state, using the existing
diagnostic. Tail calls from ordinary subprograms keep their current
behavior.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a6c22c91b6284e4713c0cf5b20ab3c9c71b77ae8
Version < 617c8266e49f45747f71e74177646a63f72b7025
Status affected
Version e3245f8990431950d20631c72236d4e8cb2dcde8
Version < 96d31b28263c429a56e4de85bcf744a5c320b3a3
Status affected
Version e3245f8990431950d20631c72236d4e8cb2dcde8
Version < 266aa4ad0b2e82397cd9045752c9bff03d98eddd
Status affected
Version 6.18.2
Version < 6.18.53
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.19
Status affected
Version 0
Version < 6.19
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/617c8266e49f45747f71e74177646a63f72b7025
https://git.kernel.org/stable/c/96d31b28263c429a56e4de85bcf744a5c320b3a3
https://git.kernel.org/stable/c/266aa4ad0b2e82397cd9045752c9bff03d98eddd