{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98044","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:19:56.071Z","datePublished":"2026-09-25T10:23:55.454Z","dateUpdated":"2026-09-25T10:23:55.454Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T10:23:55.454Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject legacy packet loads from callbacks\n\ncheck_ld_abs() models a failed BPF_LD_ABS or BPF_LD_IND in a\nsubprogram as an implicit return with R0 set to zero. It calls\nprepare_func_exit() to explore this synthesized path.\n\nWhen the load is reached directly from a synchronous callback,\nprepare_func_exit() enforces the callback return contract and marks R0\nprecise. R0 is not derived from a real instruction on this path, so\nprecision backtracking reaches the callback call with R0 still requested\nand triggers the \"callback unexpected regs\" verifier bug. A privileged\nprogram loader can therefore cause a verifier warning and an -EFAULT\nBPF_PROG_LOAD.\n\nThese legacy packet-load instructions are deprecated. Reject them from\ncallbacks rather than complicating their implicit-return model. Check all\nactive frames before constructing the implicit return so nested static\nsubprograms cannot hide the callback context.\n\nGlobal functions are verified independently with a fresh frame zero, so\nan active-frame check cannot identify a global function called from a\ncallback. Also check the complete subprogram call graph during stack-depth\nvalidation and reject a function containing a legacy load when any caller\nis a callback. This covers global and static descendants without making\nhas_ld_abs transitive, preserving its per-function BTF return-type check.\nOrdinary uses outside callbacks remain supported."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337","lessThan":"3484a99303912db62428494a9061212049027e57","status":"affected","versionType":"git"},{"version":"ee861486e377edc55361c08dcbceab3f6b6577bd","lessThan":"bc489c0c9b8c86bd7fac42cfd1bb152f042fca56","status":"affected","versionType":"git"},{"version":"ee861486e377edc55361c08dcbceab3f6b6577bd","lessThan":"e7d28823c662128caae63f14e16bd394916c139b","status":"affected","versionType":"git"},{"version":"928d354ae3557e8f755a227e67be88034eb3cd7f","status":"affected","versionType":"git"},{"version":"8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe","status":"affected","versionType":"git"},{"version":"de1055e7f9e67af32b1f3376066272b04e5223c0","status":"affected","versionType":"git"},{"version":"37ad2bb11e9de92cb7b94548705eeedd87f7d392","status":"affected","versionType":"git"},{"version":"8674e2db06cff6b50f2216eed9a761d15425bb34","status":"affected","versionType":"git"},{"version":"d846d83bdacbd8f14fc45c63b8c1d22608452e1c","status":"affected","versionType":"git"},{"version":"6.18.42","lessThan":"6.18.53","status":"affected","versionType":"semver"},{"version":"5.10.265","lessThan":"5.11","status":"affected","versionType":"semver"},{"version":"5.15.216","lessThan":"5.16","status":"affected","versionType":"semver"},{"version":"6.1.183","lessThan":"6.2","status":"affected","versionType":"semver"},{"version":"6.6.148","lessThan":"6.7","status":"affected","versionType":"semver"},{"version":"6.12.101","lessThan":"6.13","status":"affected","versionType":"semver"},{"version":"7.0.10","lessThan":"7.1","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.7","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.42","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.10"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3484a99303912db62428494a9061212049027e57"},{"url":"https://git.kernel.org/stable/c/bc489c0c9b8c86bd7fac42cfd1bb152f042fca56"},{"url":"https://git.kernel.org/stable/c/e7d28823c662128caae63f14e16bd394916c139b"}],"title":"bpf: Reject legacy packet loads from callbacks","x_generator":{"engine":"bippy-1.2.0"}}}}