BPF Update Vulnerability in Linux Kernel Affecting Performance Monitoring Features
CVE-2026-98149

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98149?

In the Linux kernel, a flaw exists that affects per-CPU array, hash, and cgroup storage map updates with BPF_F_CPU or BPF_F_ALL_CPUS not being utilized correctly. The issue arises from the incorrect handling of CPU IDs when updating values, leading to potential out-of-bounds reads and incorrect data assignments. The vulnerability specifically manifests in scenarios where the possible CPU IDs are non-contiguous. This flaw affects performance monitoring capabilities and requires careful attention from users to ensure secure and accurate operations.

Affected Version(s)

Linux 8eb76cb03f0f6c2bd7b15cf45dcffcd6bd07a360

Linux 8eb76cb03f0f6c2bd7b15cf45dcffcd6bd07a360 < 75b0a6db4300e4c2c9e97a0848deaa7acfb42fb7

Linux 7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.