Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-98041
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to incorrect branch prediction in the BPF verifier's is_branch_taken function when processing 32-bit BPF jump comparisons between pointers and zero. A local user can load a BPF program containing a 32-bit pointer-versus-zero comparison to compromise confidentiality, integrity, and availability.