CVE-2026-98084

In the Linux kernel, the following vulnerability has been resolved: bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks When processing calls to bpf_loop() verifier marks R1 (and R4) as precise. R1 tracks loop iterations number and because of the 'callback_depth < R1' mechanics in check_helper_call() must be marked precise. However, precision propagation for R1 was broken, when bpf_loop() call was verified on a second iteration. Consider the following verification trace: - main: bpf_loop(nr_loops, callback ...) - callback: BPF_EXIT - main: bpf_loop(nr_loops, callback ...) - ... While the first visit of the call to bpf_loop() propagated R1 precision as expected, the second call to mark_chain_precision() in the check_helper_call() set R1, but it was immediately reset when backtrack_insn() processed preceding BPF_EXIT in the loop deleted in this patch. Because of that, the second visit of the call to bpf_loop() injected checkpoint with R1 not marked as precise. Which could trick the verifier into accepting unsafe programs. See the next patch for an example of such program. Commit is structured in a way to minimize conflicts when 'bpf' would be eventually merged with 'bpf-next'.

Package Linux Kernel
Published 2026-09-25
Last modified 2026-09-30
Patch available
Yes

Affected versions

Linux kernel versions 6.6.15, 6.7 and later are affected. Fixed in 7.2.7, 7.3-rc2 and their respective stable series.

Affected from
≥ 6.6.15 ≥ 6.7
Fixed in
✓ 7.2.7 7.2.x ✓ 7.3-rc2

Frequently asked questions

  • What is CVE-2026-98084?

    CVE-2026-98084 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.6.15 onward and has been patched in 7.2.7 and 7.3-rc2. CVE-2026-98084 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-98084?

    Yes. CVE-2026-98084 has been patched. Fixed versions include 7.2.7 and 7.3-rc2. If you are running Linux kernel 6.6.15 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-98084 actively exploited?

    No. CVE-2026-98084 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.