๐Ÿ” CVE Alert

CVE-2026-98378

UNKNOWN 0.0

bpf: Skip unsettled links in link iterator

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Skip unsettled links in link iterator bpf_link_prime() inserts a link into link_idr before anon_inode_getfile() succeeds and before bpf_link_settle() publishes the ID in link->id. bpf_link_by_id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check. If anon_inode_getfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpf_link_put() accesses freed memory. Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as bpf_link_by_id() does. BUG: KASAN: slab-use-after-free in bpf_link_put Write of size 8 by task exp/384 Call Trace: bpf_link_put kernel/bpf/syscall.c:3372 bpf_link_seq_next kernel/bpf/link_iter.c:33 bpf_seq_read kernel/bpf/bpf_iter.c:158 vfs_read fs/read_write.c:572 ksys_read fs/read_write.c:716 do_syscall_64 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121 Kernel panic - not syncing: KASAN: panic_on_warn set ...

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
9f88361273082825d9f0d13a543d49f9fa0d44a8 < 68930f8d40ab4c10ca3b019f076136758fd100a8 9f88361273082825d9f0d13a543d49f9fa0d44a8 < c251ed48bd9063cf7de6049421e78b6de989060f 9f88361273082825d9f0d13a543d49f9fa0d44a8 < 798a61edbc436cacdb659927d067368eeb1e30e2 9f88361273082825d9f0d13a543d49f9fa0d44a8 < 6e271f093d15d323f42de26f66556af53fa8e19f 9f88361273082825d9f0d13a543d49f9fa0d44a8 < 87ce4b53b7436b50fc984f0a6afaf77f68ac5573 9f88361273082825d9f0d13a543d49f9fa0d44a8 < 50e80e2bb5e2be8515205b9c496b9640ddefa434
Linux / Linux
5.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/68930f8d40ab4c10ca3b019f076136758fd100a8 git.kernel.org: https://git.kernel.org/stable/c/c251ed48bd9063cf7de6049421e78b6de989060f git.kernel.org: https://git.kernel.org/stable/c/798a61edbc436cacdb659927d067368eeb1e30e2 git.kernel.org: https://git.kernel.org/stable/c/6e271f093d15d323f42de26f66556af53fa8e19f git.kernel.org: https://git.kernel.org/stable/c/87ce4b53b7436b50fc984f0a6afaf77f68ac5573 git.kernel.org: https://git.kernel.org/stable/c/50e80e2bb5e2be8515205b9c496b9640ddefa434