Type Confusion in Linux kernel - CVE-2026-98039
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to perform arbitrary kernel read and write operations.
The vulnerability exists due to improper type validation in map_kptr_match_type() when storing a non-per-CPU pointer in a BPF_KPTR_PERCPU map field. A local user can load a crafted BPF program that stores a plain allocation or referenced kernel pointer in the field to perform arbitrary kernel read and write operations.