CVE-2026-98044
CVE CVE-2026-98044EUVD EUVD-2026-86697Published 2026-09-25T10:23:55.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject legacy packet loads from callbacks check_ld_abs() models a failed BPF_LD_ABS or BPF_LD_IND in a subprogram as an implicit return with R0 set to zero. It calls prepare_func_exit() to explore this synthesized path. When the load is reached directly from a synchronous callback, prepare_func_exit() enforces the callback return contract and marks R0 precise. R0 is not derived from a real instruction on this path, so precision backtracking reaches the callback call with R0 still requested and triggers the "callback unexpected regs" verifier bug. A privileged program loader can therefore cause a verifier warning and an -EFAULT BPF_PROG_LOAD. These legacy packet-load instructions are deprecated. Reject them from callbacks rather than complicating their implicit-return model. Check all active frames before constructing the implicit return so nested static subprograms cannot hide the callback context. Global functions are verified independently with a fresh frame zero, so an active-frame check cannot identify a global function called from a callback. Also check the complete subprogram call graph during stack-depth validation and reject a function containing a legacy load when any caller is a callback. This covers global and static descendants without making has_ld_abs transitive, preserving its per-function BTF return-type check. Ordinary uses outside callbacks remain supported.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 6.6.148 <6.7; patch: 0; 6.18.42 <6.18.53; ee861486e377edc55361c08dcbceab3f6b6577bd <bc489c0c9b8c86bd7fac42cfd1bb152f042fca56; de1055e7f9e67af32b1f3376066272b04e5223c0; 7.1; ee861486e377edc55361c08dcbceab3f6b6577bd <e7d28823c662128caae63f14e16bd394916c139b; 5.10.265 <5.11; 6.12.101 <6.13; 928d354ae3557e8f755a227e67be88034eb3cd7f; 8674e2db06cff6b50f2216eed9a761d15425bb34; patch: 7.3-rc2; ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337 <3484a99303912db62428494a9061212049027e57; 5.15.216 <5.16; 6.1.183 <6.2; 8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe; patch: 6.18.53; 37ad2bb11e9de92cb7b94548705eeedd87f7d392; patch: 7.2.7; 7.0.10 <7.1; d846d83bdacbd8f14fc45c63b8c1d22608452e1c
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.