CVE-2026-98085
CVE CVE-2026-98085EUVD EUVD-2026-86915Published 2026-09-25T10:24:20.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge Nicholas Carlini reported a bug in precision backtracking mechanism for BPF_LD | BPF_{IND,ABS} instructions. These instructions are modelled as two branches: - fallthrough; - implicit exit from current subprogram. The implicit exit case was not handled by the backtrack_insn() function. When backtracking such a path backtrack_insn() did not call bt_subprog_enter(), which meant that backtracking continued manipulating precision marks in a caller frame, while looking at instructions in a callee frame. This lead to segmentation faults during verification (see the selftest), or unsound state pruning.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337; patch: 7.3-rc2; 6.6.148 <6.7; 6.12.101 <6.13; 37ad2bb11e9de92cb7b94548705eeedd87f7d392; 928d354ae3557e8f755a227e67be88034eb3cd7f; de1055e7f9e67af32b1f3376066272b04e5223c0; 5.15.216 <5.16; ee861486e377edc55361c08dcbceab3f6b6577bd <387b1baefbb776e3f48dc2261e77a49213f470f7; 8674e2db06cff6b50f2216eed9a761d15425bb34; patch: 0; 7.1; 8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe; ee861486e377edc55361c08dcbceab3f6b6577bd <671b7b9a660ef15b25faa3df161205b9dc8d1eb2; 5.10.265 <5.11; 6.1.183 <6.2; d846d83bdacbd8f14fc45c63b8c1d22608452e1c; 7.0.10 <7.1; patch: 7.2.7; 6.18.42 <6.19
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.