Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-98019
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect BPF verifier state pruning.
The vulnerability exists due to failure to mark scalar registers precise in the BPF verifier's check_func_arg() and check_helper_call() functions when handling nullable function arguments or zero bpf_get_local_storage() flags. A local user can submit BPF code that triggers the affected verification paths to cause incorrect BPF verifier state pruning.