CVE-2026-98378
Received Received - Intake

Use-After-Free in Linux Kernel BPF Link Iterator

Vulnerability report for CVE-2026-98378, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Skip unsettled links in link iterator bpf_link_prime() inserts a link into link_idr before anon_inode_getfile() succeeds and before bpf_link_settle() publishes the ID in link->id. bpf_link_by_id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check. If anon_inode_getfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpf_link_put() accesses freed memory. Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as bpf_link_by_id() does. BUG: KASAN: slab-use-after-free in bpf_link_put Write of size 8 by task exp/384 Call Trace: bpf_link_put kernel/bpf/syscall.c:3372 bpf_link_seq_next kernel/bpf/link_iter.c:33 bpf_seq_read kernel/bpf/bpf_iter.c:158 vfs_read fs/read_write.c:572 ksys_read fs/read_write.c:716 do_syscall_64 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121 Kernel panic - not syncing: KASAN: panic_on_warn set ...

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Linux Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8
Linux Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8
Linux Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8
Linux Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8
Linux Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8
Linux Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8
Linux Linux 5.19

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem. It occurs when a BPF link is created but not properly settled, leading to a dangling reference in the link iterator. When the iterator tries to access this freed memory, it causes a kernel panic due to a slab-use-after-free error.

Detection Guidance

This vulnerability is specific to the Linux kernel's BPF (Berkeley Packet Filter) subsystem and requires kernel-level detection. There are no direct network or system commands to detect this issue as it involves a race condition in kernel memory management. The vulnerability manifests as a use-after-free error in the BPF link iterator, which can only be detected through kernel logs or crash dumps showing KASAN (Kernel Address Sanitizer) errors related to bpf_link_put.

Impact Analysis

This vulnerability can cause system instability, including kernel panics and crashes, which may lead to denial-of-service conditions. Attackers could exploit it to execute arbitrary code in the kernel, gaining elevated privileges or causing system outages.

Mitigation Strategies

Apply the latest kernel security patches that address this issue. Since this is a Linux kernel vulnerability, update your kernel to a version that includes the fix for the BPF link iterator issue. Monitor kernel logs for KASAN errors or crashes related to BPF operations. If you cannot patch immediately, consider disabling BPF functionality if not required by your system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98378. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart