Improper input validation in Linux kernel - CVE-2026-98150
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper input validation in bpf_map_check_op_flags() when processing BPF map operations using BPF_F_CPU. A local user can issue raw bpf() system calls with an invalid CPU ID to compromise confidentiality, integrity, and availability.
The issue affects systems with sparse CPU IDs, where CPU IDs may be absent from the possible CPU mask.