CVE-2026-98384
Received Received - Intake

Out-of-Bounds Read in Linux Kernel BPF

Vulnerability report for CVE-2026-98384, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() sk_protocol lives in struct sock, not in struct sock_common. A timewait or request sock handed to bpf_sock_destroy() by the tcp iterator is neither, so reading sk->sk_protocol runs past the object: ================================================================== BUG: KASAN: slab-out-of-bounds in bpf_sock_destroy+0xc7/0xe0 Read of size 2 at addr ffff8881047d11b4 by task test_progs/428 Tainted: [W]=WARN Call Trace: <TASK> dump_stack_lvl+0x91/0xf0 print_report+0xd1/0x630 kasan_report+0xf3/0x130 __asan_report_load2_noabort+0x14/0x30 bpf_sock_destroy+0xc7/0xe0 bpf_prog_c3dd61f9d9cd9f37_iter_tcp6_timewait+0x9f/0xb7 bpf_iter_run_prog+0x538/0xde0 bpf_iter_tcp_seq_show+0x26b/0x4b0 bpf_seq_read+0x424/0x1210 vfs_read+0x197/0xe40 ksys_read+0x119/0x240 __x64_sys_read+0x72/0xc0 x64_sys_call+0x647/0x27e0 do_syscall_64+0xe5/0x610 entry_SYSCALL_64_after_hwframe+0x76/0x7e Only check sk_protocol on full socks. tcp_abort() already knows how to deal with TIME_WAIT and NEW_SYN_RECV socks. Also fix the comment, it never matched the code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
Linux Linux 4ddbcb886268af8d12a23e6640b39d1d9c652b1b
Linux Linux 4ddbcb886268af8d12a23e6640b39d1d9c652b1b
Linux Linux 4ddbcb886268af8d12a23e6640b39d1d9c652b1b
Linux Linux 4ddbcb886268af8d12a23e6640b39d1d9c652b1b
Linux Linux 4ddbcb886268af8d12a23e6640b39d1d9c652b1b
Linux Linux 6.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where an out-of-bounds read occurs in the BPF subsystem. The issue happens in bpf_sock_destroy() when it tries to read sk_protocol from a sock structure that is not a full sock or sock_common. This causes the code to read past the intended memory boundary, leading to a slab-out-of-bounds error.

Detection Guidance

This vulnerability is specific to the Linux kernel's BPF (Berkeley Packet Filter) implementation and may not have direct network detection commands. Monitor kernel logs for KASAN (Kernel Address Sanitizer) errors indicating slab-out-of-bounds reads in bpf_sock_destroy. Check for crashes or warnings in BPF-related processes using commands like dmesg | grep -i kasan or journalctl -k | grep -i kasan.

Impact Analysis

This vulnerability could allow an attacker to read unauthorized memory, potentially leading to information disclosure or system instability. It affects the Linux kernel's BPF functionality, which is used for network monitoring and security tools.

Compliance Impact

This vulnerability is a Linux kernel out-of-bounds read issue in the BPF subsystem that could lead to memory corruption or crashes. It does not directly affect compliance with standards like GDPR or HIPAA, as those focus on data protection and privacy rather than kernel memory safety.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If immediate patching is not possible, consider disabling BPF-related functionality temporarily or restricting access to BPF tools. Monitor system stability and kernel logs for signs of exploitation or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98384. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart