๐Ÿ” CVE Alert

CVE-2026-98060

UNKNOWN 0.0

bpf: Reject resilient lock operations in rbtree callbacks

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject resilient lock operations in rbtree callbacks __bpf_rbtree_add() keeps parent and link pointers live across calls to the program-supplied comparison callback. The verifier therefore requires the root's lock to remain held throughout the callback. The helper path enforces this rule for bpf_spin_lock() and bpf_spin_unlock(), but the resilient lock kfunc argument path does not. Since resilient locks may protect BPF rbtree roots, a callback can release the root lock and let another CPU remove and free the node referenced by the in-progress tree walk. The walk then resumes using freed pointers. Reject resilient lock kfuncs in an rbtree comparison callback, matching the existing policy for the spin lock helpers. Resilient-lock-protected trees remain valid when their comparison callbacks leave lock state alone.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0de2046137f976e7302d43ac01d9894d07ac1fff < cc2e065ed206aecd9b94564779244f3ffb26e356 0de2046137f976e7302d43ac01d9894d07ac1fff < 71930202a0a0c49f0a3b45b41907a074cb780266 0de2046137f976e7302d43ac01d9894d07ac1fff < 7b7b8b5960102566bd625ae829d1f330c5b5d104
Linux / Linux
6.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/cc2e065ed206aecd9b94564779244f3ffb26e356 git.kernel.org: https://git.kernel.org/stable/c/71930202a0a0c49f0a3b45b41907a074cb780266 git.kernel.org: https://git.kernel.org/stable/c/7b7b8b5960102566bd625ae829d1f330c5b5d104