SB2026092841 - Improper input validation in Linux kernel bpf_map_check_op_flags()
Published: September 28, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-98150)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper input validation in bpf_map_check_op_flags() when processing BPF map operations using BPF_F_CPU. A local user can issue raw bpf() system calls with an invalid CPU ID to compromise confidentiality, integrity, and availability.
The issue affects systems with sparse CPU IDs, where CPU IDs may be absent from the possible CPU mask.
Remediation
Install update from vendor's website.