Improper access control in Linux kernel - CVE-2026-98047
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to improper enforcement of rbtree callback restrictions in the BPF verifier's in_rbtree_lock_required_cb() function when executing static subprogram calls from bpf_rbtree_add() comparator callbacks. A local user can release the root lock, remove and drop the node being compared, and relock the tree, causing native insertion to use stale pointers to freed memory.