Vulnerability in Linux Kernel Affecting BPF Functionality
CVE-2026-98383
What is CVE-2026-98383?
A vulnerability in the Linux Kernel's BPF (Berkeley Packet Filter) functionality has been identified, specifically in the handling of LWT_SEG6LOCAL programs. This flaw permits an LWT_SEG6LOCAL program to compromise its cached Segment Routing Header (SRH) through the use of bpf_lwt_seg6_adjust_srh(), subsequently calling bpf_skb_pull_data(). This may lead to the reallocation of skb->head, resulting in a dangling pointer for the per-CPU SRH. Affected systems could face an increased risk of exploit due to unsafe combinations of helper functions within the BPF environment, necessitating the restriction of bpf_skb_pull_data() for LWT_SEG6LOCAL programs.
Affected Version(s)
Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44 < 0f38472a2aa8704a6b514c0dfa9c32f3672b8f32
Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44 < 9f9e57b5a3a033f95f49ef9d541340cdbcb80abb