Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-98085
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of an implicit subprogram exit edge in the BPF verifier's backtrack_insn() function when verifying BPF_LD | BPF_{IND,ABS} instructions. A local user can submit crafted BPF instructions for verification to cause a denial of service.
These instructions are modeled as fallthrough and implicit subprogram exit branches.