CVE-2026-98039
CVE CVE-2026-98039EUVD EUVD-2026-86692Published 2026-09-25T10:23:52.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: bpf: Require MEM_PERCPU for percpu kptr stores map_kptr_match_type() treats perm_flags as the set of register type flags that a kptr field permits. Adding MEM_PERCPU to that set for BPF_KPTR_PERCPU does not require the source register to carry it, however. The subset test consequently accepts both a plain bpf_obj_new() allocation and a referenced kernel pointer into a __percpu_kptr map field. Loads from the field are always marked MEM_PERCPU. Consumers then treat the stored value as the cookie returned by bpf_percpu_obj_new(): per-CPU pointer helpers relocate it, and map teardown selects the per-CPU free path. A plain allocation can therefore provide an arbitrary kernel read/write, while a kernel pointer can be relocated into an invalid address or sent through a missing destructor. Require the source MEM_PERCPU flag to match the destination field kind. This preserves valid bpf_percpu_obj_new() stores and rejects both the program-BTF and kernel-BTF variants.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 36d8bdf75a93190e5669b9d1d95994e13e15ba1d <0bdd6121c8dd5f1764efe701ce26bb8e15acb172; 36d8bdf75a93190e5669b9d1d95994e13e15ba1d <048029ba1c793f8cabc4ad5eea765da01903f8f1; patch: 6.12.111; patch: 7.2.7; 36d8bdf75a93190e5669b9d1d95994e13e15ba1d <aaa9cf7707d1c5c0d2ca9d40c8b71652ac1c3c3f; 6.7; patch: 0; 36d8bdf75a93190e5669b9d1d95994e13e15ba1d <ad4ebae5dbc2d47b544aa54f03c12490065be08a; patch: 6.18.53; patch: 7.3-rc2
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.