Improper input validation in Linux kernel - CVE-2026-98075
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the BPF verifier when loading a BPF program that references the main program as a callback. A local user can load a crafted BPF program using a BPF_PSEUDO_FUNC reference to the main program to cause a denial of service.