SB20260928152 - Improper access control in Linux kernel bpf



SB20260928152 - Improper access control in Linux kernel bpf

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB20260928152
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-98047)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to improper enforcement of rbtree callback restrictions in the BPF verifier's in_rbtree_lock_required_cb() function when executing static subprogram calls from bpf_rbtree_add() comparator callbacks. A local user can release the root lock, remove and drop the node being compared, and relock the tree, causing native insertion to use stale pointers to freed memory.


Remediation

Install update from vendor's website.