CVE-2026-98383
Received Received - Intake

BPF Helper Restriction in Linux Kernel

Vulnerability report for CVE-2026-98383, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL An LWT_SEG6LOCAL program can invalidate its cached SRH with bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter may reallocate skb->head, leaving the per-CPU SRH pointer dangling. Post-program SRH validation then writes through that pointer. Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier rejects this unsafe helper combination. Other LWT program types continue to expose the helper through lwt_out_func_proto().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44
Linux Linux 4.18

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the BPF (Berkeley Packet Filter) subsystem. Specifically, it affects LWT_SEG6LOCAL programs that use bpf_skb_pull_data() after invalidating their cached SRH (Segment Routing Header) with bpf_lwt_seg6_adjust_srh(). This sequence can cause the skb->head to be reallocated, leaving the SRH pointer dangling. Subsequent validation writes through this invalid pointer, leading to potential memory corruption or crashes.

Impact Analysis

If you use Linux systems with BPF and LWT_SEG6LOCAL programs, this vulnerability could cause system instability, crashes, or unexpected behavior. Attackers might exploit it to trigger denial-of-service conditions or execute arbitrary code with kernel privileges, depending on the system configuration.

Mitigation Strategies

Update the Linux kernel to a patched version that disallows bpf_skb_pull_data() for LWT_SEG6LOCAL programs. This prevents the unsafe helper combination that leads to the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98383. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart