Linux Kernel Vulnerability Affecting Dev-Bound Programs
CVE-2026-98382

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-98382?

A vulnerability in the Linux kernel allows bound-only BPF programs to be improperly executed on unrelated network devices, leading to potential memory corruption issues. The flaw occurs when programs fall back to comparing off-device pointers after failing to match exact network device pointers. This can allow malicious actors with elevated privileges (CAP_BPF and CAP_NET_ADMIN) to create links that execute metadata functions on an unintended device, causing null pointer dereferences and kernel panics. The issue can particularly affect setups using virtual Ethernet devices, leading to severe system instability. It is essential to restrict non-offloaded programs to exact network device matches to mitigate this type of vulnerability.

Affected Version(s)

Linux 2b3486bc2d237ec345b3942b7be5deabf8c8fed1

Linux 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < 0dceda331180617aeeb22381e8480b37f18ba08b

Linux 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < 940b626854de200e6187777d42114727daca617c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.