Incorrect calculation in Linux kernel - CVE-2026-98151
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a verifier warning.
The vulnerability exists due to inconsistent synchronization of 32-bit register bounds and pointer offset state in the BPF verifier when verifying speculative pointer arithmetic in an unprivileged BPF program. A local user can load a BPF program that performs bounded scalar arithmetic on a map-value pointer to trigger a verifier warning.
The warning occurs when the verifier evaluates a subsequent register copy along a speculative path.