Answer in brief
CVE-2026-98060 records a Unknown severity vulnerability in bpf: Reject resilient lock operations in rbtree callbacks. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0de2046137f976e7302d43ac01d9894d07ac1fff <cc2e065ed206aecd9b94564779244f3ffb26e356 || >=0de2046137f976e7302d43ac01d9894d07ac1fff <71930202a0a0c49f0a3b45b41907a074cb780266 || >=0de2046137f976e7302d43ac01d9894d07ac1fff <7b7b8b5960102566bd625ae829d1f330c5b5d104 | cc2e065ed206aecd9b94564779244f3ffb26e356, 71930202a0a0c49f0a3b45b41907a074cb780266, 7b7b8b5960102566bd625ae829d1f330c5b5d104 |
| Linux/Linuxgeneric | 6.15 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject resilient lock operations in rbtree callbacks __bpf_rbtree_add() keeps parent and link pointers live across calls to the program-supplied comparison callback. The verifier therefore requires the root's lock to remain held throughout the callback. The helper path enforces this rule for bpf_spin_lock() and bpf_spin_unlock(), but the resilient lock kfunc argument path does not. Since resilient locks may protect BPF rbtree roots, a callback can release the root lock and let another CPU remove and free the node referenced by the in-progress tree walk. The walk then resumes using freed pointers. Reject resilient lock kfuncs in an rbtree comparison callback, matching the existing policy for the spin lock helpers. Resilient-lock-protected trees remain valid when their comparison callbacks leave lock state alone.
Quoted source text, attributed separately from HOL analysis.