Improper input validation in Linux kernel - CVE-2026-98150

 

Improper input validation in Linux kernel - CVE-2026-98150

Published: September 28, 2026


Vulnerability identifier: #VU152290
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98150
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper input validation in bpf_map_check_op_flags() when processing BPF map operations using BPF_F_CPU. A local user can issue raw bpf() system calls with an invalid CPU ID to compromise confidentiality, integrity, and availability.

The issue affects systems with sparse CPU IDs, where CPU IDs may be absent from the possible CPU mask.


Affected software

Linux kernel

How to mitigate CVE-2026-98150

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins