XDP Program Pointer Management Vulnerability in Linux Kernel veth Components
CVE-2026-98381

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-98381?

A vulnerability in the Linux kernel's veth network interface can lead to improper handling of XDP program pointers during channel resizing. When channels are removed, associated XDP resources are torn down, yet the pointers remain intact. If these outdated pointers are referenced later during operations such as re-enabling NAPI or channel increases, it may cause significant system instability, including kernel panics due to dereferencing freed memory. This flaw emphasizes the importance of meticulous resource management for network components to ensure system reliability and security.

Affected Version(s)

Linux 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 < 7a8e143109ff2736dc79e41dcd55af7ceab7520a

Linux 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 < 1a5c5b9c64ba5f39dba55da6e12561ca56eeb758

Linux 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.