SB2026092841 - Improper input validation in Linux kernel bpf_map_check_op_flags()



SB2026092841 - Improper input validation in Linux kernel bpf_map_check_op_flags()

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092841
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-98150)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper input validation in bpf_map_check_op_flags() when processing BPF map operations using BPF_F_CPU. A local user can issue raw bpf() system calls with an invalid CPU ID to compromise confidentiality, integrity, and availability.

The issue affects systems with sparse CPU IDs, where CPU IDs may be absent from the possible CPU mask.


Remediation

Install update from vendor's website.