Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-98048
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect eBPF program behavior.
The vulnerability exists due to improper control flow handling in the BPF verifier fastcall pattern rewrite logic when processing a spill-call-fill instruction sequence entered by a jump. A local user can load an eBPF program containing such a sequence to cause incorrect eBPF program behavior.