CVE-2026-98273
Received Received - Intake

Kernel Crash in Linux x86 kprobes Due to CS CALL Instruction Handling

Vulnerability report for CVE-2026-98273, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: x86/kprobes: Fix crash when probing CS CALL instructions When using eBPF to probe CS CALL instructions within a function, a crash can be triggered. The eBPF tool probes offset 257 of the __hrtimer_run_queues() function: <__hrtimer_run_queues+249>: nopl 0x0(%rax,%rax,1) <__hrtimer_run_queues+254>: mov %r14,%rdi <__hrtimer_run_queues+257>: cs call <__x86_indirect_thunk_r12> <__hrtimer_run_queues+263>: mov %eax,%r12d <__hrtimer_run_queues+266>: xchg %ax,%ax <__hrtimer_run_queues+268>: mov %r13,%rdi Which triggers this crash: BUG: unable to handle page fault for address: 00000000000f41c9 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page PGD 0 P4D 0 Oops: 0002 [#1] SMP NOPTI CPU: 1 PID: 0 Comm: swapper/1 Kdump: loaded Tainted: P RIP: 0010:__hrtimer_run_queues+0x106/0x230 Note that __hrtimer_run_queues+0x106 is __hrtimer_run_queues+262, which is at the 6th byte of the above CS CALL instruction. Since the CS CALL instruction occupies 6 bytes, the exception occurred in the middle of that call instruction. The root cause is that when using eBPF tools to probe in the middle of a function, a kprobe with INT3 is used as the underlying implementation. During single-step emulation of the original CALL instruction, int3_emulate_call() assumes that the probed CALL instruction is 5 bytes long. However, the actual CS-prefixed CALL instruction occupies 6 bytes, so it constructs an incorrect exception return address. When the CPU returns from the kprobe handler, the next instruction to be executed is at the address of the last byte of that CS CALL instruction. Coincidentally, starting from that address, the CPU fetches and decodes a completely different instruction, which ultimately triggers a kernel crash. Fix the issue by using the actual instruction length obtained from the instruction decoder when constructing the exception return address, rather than relying on the hardcoded CALL_INSN_SIZE macro. [ mingo: Refined the changelog ]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
Linux Linux 6256e668b7af9d81472e03c6a171630c08f8858a
Linux Linux 6256e668b7af9d81472e03c6a171630c08f8858a
Linux Linux 6256e668b7af9d81472e03c6a171630c08f8858a
Linux Linux ba7d1dae9fe866abe74bb1e849fb85983b7c4c37
Linux Linux 5.10.190
Linux Linux 5.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a crash when probing CS CALL instructions using eBPF tools. The issue occurs because the kernel incorrectly handles the length of a CS-prefixed CALL instruction during single-step emulation. The crash happens when the CPU returns from the kprobe handler to an incorrect address, leading to execution of unintended instructions and a kernel crash.

Detection Guidance

This vulnerability is specific to the Linux kernel and involves a crash when probing CS CALL instructions using eBPF tools. Detection requires checking kernel logs for crashes related to __hrtimer_run_queues or kprobe handlers. No direct network detection commands are applicable.

Impact Analysis

This vulnerability can cause system instability or crashes when eBPF tools are used to probe certain kernel functions. It may lead to kernel panics, data corruption, or denial of service if exploited maliciously or triggered accidentally during debugging.

Mitigation Strategies

Apply the Linux kernel patch that fixes the issue by using the correct instruction length for CS CALL instructions. Update to a kernel version containing the fix. If immediate patching is not possible, avoid using eBPF tools to probe CS CALL instructions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98273. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart