← All Advisories

CVE-2026-98075

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98075

Key Details

CVECVE-2026-98075
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bpf: reject BPF_PSEUDO_FUNC reference to the main program

fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real

function addresses. This function is invoked from bpf_jit_subprogs()

only when env->subprog_cnt > 1. Meaning that for any program like

below:

int main(void *ctx) {

void *ptr = main;

...

bpf_timer_set_callback(..., ptr);

...

}

The 'ptr' won't be ever converted to contain an address.

In combination with e.g. bpf_timer_set_callback() this would lead to a

function call at a bogus address.

Instead of complicating the implementation, just assume that no useful

program needs main to be a sync or async callback and reject

BPF_PSEUDO_FUNC loads for the main subprogram. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98075
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98075