Improper input validation in Linux kernel - CVE-2026-98132
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect BPF verifier precision propagation.
The vulnerability exists due to improper verifier state handling in __clean_func_state() in kernel/bpf/states.c when cleaning function state for an 8-byte scalar zero stack spill with a half-dead slot. A local user can trigger the affected stack-state cleanup to cause incorrect BPF verifier precision propagation.