← All Advisories

Linux Kernel BPF Verifier Fails to Reject Legacy Packet Loads from Callback Subprograms, Which Can Model a Failed BPF_LD_ABS as an Implicit Zero Return Causing Incorrect Program Behavior

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-98044

Key Details

CVECVE-2026-98044

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject legacy packet loads from callbacks

check_ld_abs() models a failed BPF_LD_ABS or BPF_LD_IND in a

subprogram as an implicit return with R0 set to zero. It calls

prepare_func_exit() to explore this synthesized path.

When the load is reached directly from a synchronous callback,

prepare_func_exit() enforces the callback return contract and marks R0

precise. R0 is not derived from a real instruction on this path, so

precision backtracking reaches the callback call with R0 still requested

and triggers the "callback unexpected regs" verifier bug. A privileged

program loader can therefore cause a verifier warning and an -EFAULT

BPF_PROG_LOAD.

These legacy packet-load instructions are deprecated. Reject them from

callbacks rather than complicating their implicit-return model. Check all

active frames before constructing the implicit return so nested static

subprograms cannot hide the callback context.

Global functions are verified independently with a fresh frame zero, so

an active-frame check cannot identify a global function called from a

callback. Also check the complete subprogram call graph during stack-depth

validation and reject a function containing a legacy load when any caller

is a callback. This covers global and static descendants without making

has_ld_abs transitive, preserving its per-function BTF return-type check.

Ordinary uses outside callbacks remain supported. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98044
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98044