Answer in brief
CVE-2026-98085 records a Unknown severity vulnerability in bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ee861486e377edc55361c08dcbceab3f6b6577bd <671b7b9a660ef15b25faa3df161205b9dc8d1eb2 || >=ee861486e377edc55361c08dcbceab3f6b6577bd <387b1baefbb776e3f48dc2261e77a49213f470f7 || 928d354ae3557e8f755a227e67be88034eb3cd7f || 8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe || de1055e7f9e67af32b1f3376066272b04e5223c0 || 37ad2bb11e9de92cb7b94548705eeedd87f7d392 || 8674e2db06cff6b50f2216eed9a761d15425bb34 || ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337 || d846d83bdacbd8f14fc45c63b8c1d22608452e1c || >=5.10.265 <5.11 || >=5.15.216 <5.16 || >=6.1.183 <6.2 || >=6.6.148 <6.7 || >=6.12.101 <6.13 || >=6.18.42 <6.19 || >=7.0.10 <7.1 | 671b7b9a660ef15b25faa3df161205b9dc8d1eb2, 387b1baefbb776e3f48dc2261e77a49213f470f7, 5.11, 5.16, 6.2, 6.7, 6.13, 6.19, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge Nicholas Carlini reported a bug in precision backtracking mechanism for BPF_LD | BPF_{IND,ABS} instructions. These instructions are modelled as two branches: - fallthrough; - implicit exit from current subprogram. The implicit exit case was not handled by the backtrack_insn() function. When backtracking such a path backtrack_insn() did not call bt_subprog_enter(), which meant that backtracking continued manipulating precision marks in a caller frame, while looking at instructions in a callee frame. This lead to segmentation faults during verification (see the selftest), or unsound state pruning.
Quoted source text, attributed separately from HOL analysis.