Memory Corruption Vulnerability in Linux Kernel's BPF Module
CVE-2026-98378

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-98378?

A vulnerability has been discovered in the Linux kernel's BPF module that can lead to memory corruption. The issue arises from how unsettled links are managed during the linking process. A link may be inserted into an ID before it has been fully established. If an error occurs afterwards, the system is left with a dangling reference which can lead to accessing freed memory, potentially causing crashes and instability. This flaw emphasizes the importance of robust memory management practices within kernel-level systems.

Affected Version(s)

Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8 < 68930f8d40ab4c10ca3b019f076136758fd100a8

Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8

Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8 < 798a61edbc436cacdb659927d067368eeb1e30e2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.