Per-CPU Array Inner Map Replacement Flaw in Linux Kernel by Linux Foundation
CVE-2026-98376

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-98376?

A vulnerability exists in the Linux kernel related to per-CPU arrays, where improper handling of the inner map replacement can lead to potential out-of-bounds access. This occurs when the function percpu_array_map_ops.map_meta_equal allows a replacement map with fewer max entries without enforcing the necessary checks. A successful attacker could exploit this flaw, leading to critical security risks. The kernel has since been patched to improve the validation process, ensuring that replacements conform to size specifications through updated comparisons.

Affected Version(s)

Linux db69718b8efac802c7cc20d5a6c7dfc913f99c43 < 593980175389a05793f6060aa20e626330960395

Linux 6.10

Linux 6.10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.