← All Advisories

CVE-2026-98007

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98007

Key Details

CVECVE-2026-98007
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject non-scalar bpf_loop iteration counts

bpf_loop() declares its nr_loops argument as ARG_ANYTHING. Privileged

programs may pass pointer values to such arguments, so check_func_arg()

lets a pointer-valued R1 reach the helper-specific checks.

Since commit bb124da69c47 ("bpf: keep track of max number of bpf_loop

callback iterations"), the verifier marks R1 precise and reads its upper

bound to limit callback simulation. Precision backtracking only accepts

scalar registers, so passing a pointer instead triggers the "backtracking

misuse" verifier warning. Kernels with panic_on_warn enabled subsequently

panic.

Introduce ARG_SCALAR for helper arguments that only accept scalar values

and use it for bpf_loop() nr_loops. Generic helper argument validation then

rejects pointers before loop inlining and precision processing. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98007
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98007