-
CVE-2026-98075
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:24:14
- Zuletzt bearbeitet 03.10.2026 11:18:28
- Erkennungen
bpf: reject BPF_PSEUDO_FUNC reference to the main program
In the Linux kernel, the following vulnerability has been resolved:
bpf: reject BPF_PSEUDO_FUNC reference to the main program
fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real
function addresses. This function is invoked from bpf_jit_subprogs()
only when env->subprog_cnt > 1. Meaning that for any program like
below:
int main(void *ctx) {
void *ptr = main;
...
bpf_timer_set_callback(..., ptr);
...
}
The 'ptr' won't be ever converted to contain an address.
In combination with e.g. bpf_timer_set_callback() this would lead to a
function call at a bogus address.
Instead of complicating the implementation, just assume that no useful
program needs main to be a sync or async callback and reject
BPF_PSEUDO_FUNC loads for the main subprogram.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
69c087ba6225b574afb6e505b72cb75242a3d844
Version <
c74750dca96f40a1adb9d334f5a3152f44b270c3
Status
affected
Version
69c087ba6225b574afb6e505b72cb75242a3d844
Version <
314c8caa9cb64ad60c5b969fe9a3e2dcdccf156f
Status
affected
Version
69c087ba6225b574afb6e505b72cb75242a3d844
Version <
8cb75f7ada25b1cf25f2f74dec3ba649b9064a09
Status
affected
Version
69c087ba6225b574afb6e505b72cb75242a3d844
Version <
118212417ba0120d99f84154799f8880f07411f4
Status
affected
Version
69c087ba6225b574afb6e505b72cb75242a3d844
Version <
d6c39774ae093c9f7009cc4ae918f18fc1af7ae7
Status
affected
Version
69c087ba6225b574afb6e505b72cb75242a3d844
Version <
92f0bd0e2b632c6565ac2214a4d7d2ed37e5b9f6
Status
affected
Version
69c087ba6225b574afb6e505b72cb75242a3d844
Version <
374b2c5561db80fcdd7cdce44af37a49416f61c7
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.13
Status
affected
Version
0
Version <
5.13
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/118212417ba0120d99f84154799f8880f07411f4
https://git.kernel.org/stable/c/d6c39774ae093c9f7009cc4ae918f18fc1af7ae7
https://git.kernel.org/stable/c/92f0bd0e2b632c6565ac2214a4d7d2ed37e5b9f6
https://git.kernel.org/stable/c/374b2c5561db80fcdd7cdce44af37a49416f61c7
https://git.kernel.org/stable/c/314c8caa9cb64ad60c5b969fe9a3e2dcdccf156f
https://git.kernel.org/stable/c/8cb75f7ada25b1cf25f2f74dec3ba649b9064a09
https://git.kernel.org/stable/c/c74750dca96f40a1adb9d334f5a3152f44b270c3