CVE-2026-98061
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject tail calls directly from callback frames A tail call from a non-zero frame is modeled as a return from that frame. The verifier makes R0 unknown and calls prepare_func_exit() for the taken branch. When the current frame is a synchronous callback, prepare_func_exit() enforces the callback return-value contract and marks R0 precise. Since the tail-call path synthesized R0 rather than deriving it from an instruction, precision backtracking reaches the callback-calling instruction with R0 still requested and triggers the "callback unexpected regs" verifier bug. A CAP_BPF task can therefore cause a WARN and an -EFAULT BPF_PROG_LOAD. Tail calls reachable from callbacks are already rejected later by check_max_stack_depth(). Reject a tail call made directly by a callback before constructing the inconsistent return state, using the existing diagnostic. Tail calls from ordinary subprograms keep their current behavior.
Affected versions
Linux kernel versions
6.18.2,
6.19
and later are affected. Fixed in
6.18.53,
7.2.7,
7.3-rc2
and their respective stable series.
References
3 totalFrequently asked questions
-
What is CVE-2026-98061?
CVE-2026-98061 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.18.2 onward and has been patched in 6.18.53, 7.2.7 and 7.3-rc2. CVE-2026-98061 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-98061?
Yes. CVE-2026-98061 has been patched. Fixed versions include 6.18.53, 7.2.7 and 7.3-rc2. If you are running Linux kernel 6.18.2 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-98061 actively exploited?
No. CVE-2026-98061 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.