CVE-2026-98037

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject untrusted allocated-object pointers When the final RCU read-side critical section ends, a local kptr is demoted to PTR_UNTRUSTED but retains MEM_ALLOC. The pointer may be NULL or may refer to an object whose lifetime is no longer protected. type_is_ptr_alloc_obj() nevertheless recognizes any PTR_TO_BTF_ID with MEM_ALLOC as a live allocated object. In particular, a refcount-only local kptr never carries NON_OWN_REF, so it still passes the bpf_refcount_acquire() argument check after RCU protection ends. The kfunc can then dereference NULL or stale memory. Make type_is_ptr_alloc_obj() reject PTR_UNTRUSTED pointers. Since type_is_non_owning_ref() is based on the same predicate, graph kfunc arguments obey the same live-object requirement. Fault-protected reads of the demoted pointer remain valid: writes are already rejected, and read fixups use bpf_may_fault_on_deref() rather than this predicate. [ kkd: Rewrote commit log ]

Package Linux Kernel
Published 2026-09-25
Last modified 2026-09-25
Patch available
Yes

Affected versions

Linux kernel versions 6.8 and later are affected. Fixed in 6.12.111, 6.18.53, 7.2.7, 7.3-rc2 and their respective stable series.

Affected from
≥ 6.8
Fixed in
✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc2

Frequently asked questions

  • What is CVE-2026-98037?

    CVE-2026-98037 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.8 onward and has been patched in 6.12.111, 6.18.53, 7.2.7 and others. CVE-2026-98037 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98037?

    Yes. CVE-2026-98037 has been patched. Fixed versions include 6.12.111, 6.18.53, 7.2.7 and others. If you are running Linux kernel 6.8 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98037 actively exploited?

    No. CVE-2026-98037 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.