Linux Kernel Vulnerability in BPF Handling Impacting Scalar Zero Spills
CVE-2026-98132

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98132?

A vulnerability in the Linux kernel's BPF subsystem allows for improper handling of scalar zero spills. This occurs when a zero value is mistakenly downgraded to a stack representation termed STACK_ZERO, disrupting precision propagation chains within the kernel. When dead values are mismanaged, it opens potential avenues for exploitation. A patch has been implemented to prevent the incorrect conversion of these stack spills, ensuring system integrity and accuracy in processing. Though more complex solutions were considered, the current fix provides a straightforward remedy to boost kernel resilience against this flaw.

Affected Version(s)

Linux be23266b4a08540aa43d8503a2ea10247c8daebe < 436fa689630b741a77ef8c4a6f426479affd5bac

Linux be23266b4a08540aa43d8503a2ea10247c8daebe < 2f3536bff8823d3c5fdbbe15e17bfca696cc2b2e

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.