CVE-2026-98007
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject non-scalar bpf_loop iteration counts bpf_loop() declares its nr_loops argument as ARG_ANYTHING. Privileged programs may pass pointer values to such arguments, so check_func_arg() lets a pointer-valued R1 reach the helper-specific checks. Since commit bb124da69c47 ("bpf: keep track of max number of bpf_loop callback iterations"), the verifier marks R1 precise and reads its upper bound to limit callback simulation. Precision backtracking only accepts scalar registers, so passing a pointer instead triggers the "backtracking misuse" verifier warning. Kernels with panic_on_warn enabled subsequently panic. Introduce ARG_SCALAR for helper arguments that only accept scalar values and use it for bpf_loop() nr_loops. Generic helper argument validation then rejects pointers before loop inlining and precision processing.
Affected versions
Linux kernel versions
6.6.15,
6.7
and later are affected. Fixed in
6.6.158,
6.12.111,
6.18.53,
7.2.7,
7.3-rc2
and their respective stable series.
References
5 totalFrequently asked questions
-
What is CVE-2026-98007?
CVE-2026-98007 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.6.15 onward and has been patched in 6.6.158, 6.12.111, 6.18.53 and others. CVE-2026-98007 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-98007?
Yes. CVE-2026-98007 has been patched. Fixed versions include 6.6.158, 6.12.111, 6.18.53 and others. If you are running Linux kernel 6.6.15 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-98007 actively exploited?
No. CVE-2026-98007 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.