CVE-2026-98376
Received Received - Intake

BPF Array Map Inner Replacement Bypass

Vulnerability report for CVE-2026-98376, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Use array_map_meta_equal for percpu array inner map replacement percpu_array_map_ops.map_meta_equal points to the generic bpf_map_meta_equal(), which does not compare max_entries. When a percpu array serves as an inner map, replacing it with one that has fewer max_entries bypasses the check. Since percpu_array_map_gen_lookup() inlines the original template's index_mask as a JIT immediate, a lookup on the replacement map can access pptrs[] out of bounds. Point percpu_array_map_ops.map_meta_equal to array_map_meta_equal(), which already enforces the max_entries equality check. Add a selftest to verify that replacing a percpu array inner map with a differently-sized one is rejected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Linux Linux db69718b8efac802c7cc20d5a6c7dfc913f99c43
Linux Linux 6.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the BPF (Berkeley Packet Filter) subsystem. The issue occurs when a percpu array inner map is replaced with another map that has fewer max_entries. The generic map_meta_equal function does not check max_entries, allowing out-of-bounds access during lookups. This happens because the original template's index_mask is inlined as a JIT immediate, leading to potential memory corruption.

Detection Guidance

This vulnerability is specific to the Linux kernel's BPF (Berkeley Packet Filter) implementation. Detection requires checking the kernel version and BPF-related configurations. Use commands like 'uname -r' to check the kernel version and 'lsmod | grep bpf' to verify BPF module usage. If the kernel is vulnerable, update to a patched version immediately.

Impact Analysis

This vulnerability could allow an attacker to execute arbitrary code or cause a denial of service by exploiting the out-of-bounds memory access. It primarily affects systems using BPF with percpu array inner maps, potentially leading to system instability or unauthorized access.

Mitigation Strategies

Apply the latest kernel updates from your Linux distribution to patch the BPF vulnerability. Reboot the system to ensure the updated kernel is active. If immediate patching is not possible, consider disabling BPF functionality temporarily as a workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98376. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart