-

CVE-2026-98382

bpf: Reject dev-bound-only programs on other devices

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject dev-bound-only programs on other devices

__bpf_offload_dev_match() falls back to comparing offdev pointers after an
exact netdev mismatch. Bound-only programs normally have NULL offdevs, so
unrelated netdevs compare equal. A bound-only program on an
offload-registered netdev can instead inherit a real offdev and match a
sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use
bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs
specialized for the bound driver on the target driver's xdp_buff. Running a
veth-bound program on tun reads beyond tun's bare stack xdp_buff as a
veth_xdp_buff.

  Oops: general protection fault, probably for non-canonical address
  KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
  RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673)
  Call Trace:
   ...
   tun_build_skb (drivers/net/tun.c:1739)
   tun_get_user (drivers/net/tun.c:1856)
   tun_chr_write_iter (drivers/net/tun.c:2091)
   vfs_write (fs/read_write.c:595 fs/read_write.c:687)
   ksys_write (fs/read_write.c:739)
   do_syscall_64 (arch/x86/entry/syscall_64.c:84)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
  Kernel panic - not syncing: Fatal exception in interrupt

Restrict non-offloaded programs to exact netdev matches and retain the
shared-offdev fallback only for genuinely offloaded multi-port programs.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1
Version < e57f04194361574493e3e6cf0b9e9c69e4ae9791
Status affected
Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1
Version < 0dceda331180617aeeb22381e8480b37f18ba08b
Status affected
Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1
Version < 940b626854de200e6187777d42114727daca617c
Status affected
Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1
Version < bb375f3c5990e29851894f20ebc4b9dbc6676126
Status affected
Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1
Version < 6db1ce73e9853f533eb7f413f14ba00f8ec6f80d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.3
Status affected
Version 0
Version < 6.3
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.55
Status unaffected
Version <= 7.2.*
Version 7.2.9
Status unaffected
Version <= *
Version 7.3-rc5
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.042
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e57f04194361574493e3e6cf0b9e9c69e4ae9791
https://git.kernel.org/stable/c/0dceda331180617aeeb22381e8480b37f18ba08b
https://git.kernel.org/stable/c/940b626854de200e6187777d42114727daca617c
https://git.kernel.org/stable/c/bb375f3c5990e29851894f20ebc4b9dbc6676126
https://git.kernel.org/stable/c/6db1ce73e9853f533eb7f413f14ba00f8ec6f80d