Answer in brief
CVE-2026-98037 records a Unknown severity vulnerability in bpf: Reject untrusted allocated-object pointers. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1b12171533a9bb23cf6fba7262b479028b65e1e8 <092c2874dc1b2060fa77a465a971acd4fdf87683 || >=1b12171533a9bb23cf6fba7262b479028b65e1e8 <135d542b97fa93e32c457d49d6e7b33ca7d05bae || >=1b12171533a9bb23cf6fba7262b479028b65e1e8 <6b1f786ad85a0b63393b76f5e634deab1a73198c || >=1b12171533a9bb23cf6fba7262b479028b65e1e8 <7441ee8276641bddaf1cba7bb75ef9c1458ceb3b | 092c2874dc1b2060fa77a465a971acd4fdf87683, 135d542b97fa93e32c457d49d6e7b33ca7d05bae, 6b1f786ad85a0b63393b76f5e634deab1a73198c, 7441ee8276641bddaf1cba7bb75ef9c1458ceb3b |
| Linux/Linuxgeneric | 6.8 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject untrusted allocated-object pointers When the final RCU read-side critical section ends, a local kptr is demoted to PTR_UNTRUSTED but retains MEM_ALLOC. The pointer may be NULL or may refer to an object whose lifetime is no longer protected. type_is_ptr_alloc_obj() nevertheless recognizes any PTR_TO_BTF_ID with MEM_ALLOC as a live allocated object. In particular, a refcount-only local kptr never carries NON_OWN_REF, so it still passes the bpf_refcount_acquire() argument check after RCU protection ends. The kfunc can then dereference NULL or stale memory. Make type_is_ptr_alloc_obj() reject PTR_UNTRUSTED pointers. Since type_is_non_owning_ref() is based on the same predicate, graph kfunc arguments obey the same live-object requirement. Fault-protected reads of the demoted pointer remain valid: writes are already rejected, and read fixups use bpf_may_fault_on_deref() rather than this predicate. [ kkd: Rewrote commit log ]
Quoted source text, attributed separately from HOL analysis.