SB2026100953 - Out-of-bounds read in Linux kernel bpf
Published: October 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-98382)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a denial of service by triggering a kernel panic.
The vulnerability exists due to an out-of-bounds read in veth_xdp_rx_timestamp() when executing veth-specific metadata kfuncs on a tun device's xdp_buff. A local privileged user can use bpf(BPF_LINK_CREATE) with a different target interface index to attach a veth-bound program to a tun device to cause a denial of service by triggering a kernel panic.
Exploitation requires both CAP_BPF and CAP_NET_ADMIN capabilities.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0dceda331180617aeeb22381e8480b37f18ba08b
- https://git.kernel.org/stable/c/6db1ce73e9853f533eb7f413f14ba00f8ec6f80d
- https://git.kernel.org/stable/c/940b626854de200e6187777d42114727daca617c
- https://git.kernel.org/stable/c/bb375f3c5990e29851894f20ebc4b9dbc6676126
- https://git.kernel.org/stable/c/e57f04194361574493e3e6cf0b9e9c69e4ae9791