Improper input validation in Linux kernel - CVE-2026-98084
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause the BPF verifier to accept unsafe programs.
The vulnerability exists due to improper precision propagation in the BPF verifier backtracking logic when verifying repeated bpf_loop() calls with callbacks. A local user can submit a crafted BPF program that repeatedly invokes bpf_loop() to cause the BPF verifier to accept unsafe programs.