Linux Kernel Vulnerability in BPF Handling Impacting Scalar Zero Spills
CVE-2026-98132
What is CVE-2026-98132?
A vulnerability in the Linux kernel's BPF subsystem allows for improper handling of scalar zero spills. This occurs when a zero value is mistakenly downgraded to a stack representation termed STACK_ZERO, disrupting precision propagation chains within the kernel. When dead values are mismanaged, it opens potential avenues for exploitation. A patch has been implemented to prevent the incorrect conversion of these stack spills, ensuring system integrity and accuracy in processing. Though more complex solutions were considered, the current fix provides a straightforward remedy to boost kernel resilience against this flaw.
Affected Version(s)
Linux be23266b4a08540aa43d8503a2ea10247c8daebe < 436fa689630b741a77ef8c4a6f426479affd5bac
Linux be23266b4a08540aa43d8503a2ea10247c8daebe < 2f3536bff8823d3c5fdbbe15e17bfca696cc2b2e
Linux 7.1