๐Ÿ” CVE Alert

CVE-2026-98382

UNKNOWN 0.0

bpf: Reject dev-bound-only programs on other devices

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject dev-bound-only programs on other devices __bpf_offload_dev_match() falls back to comparing offdev pointers after an exact netdev mismatch. Bound-only programs normally have NULL offdevs, so unrelated netdevs compare equal. A bound-only program on an offload-registered netdev can instead inherit a real offdev and match a sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs specialized for the bound driver on the target driver's xdp_buff. Running a veth-bound program on tun reads beyond tun's bare stack xdp_buff as a veth_xdp_buff. Oops: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673) Call Trace: ... tun_build_skb (drivers/net/tun.c:1739) tun_get_user (drivers/net/tun.c:1856) tun_chr_write_iter (drivers/net/tun.c:2091) vfs_write (fs/read_write.c:595 fs/read_write.c:687) ksys_write (fs/read_write.c:739) do_syscall_64 (arch/x86/entry/syscall_64.c:84) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Kernel panic - not syncing: Fatal exception in interrupt Restrict non-offloaded programs to exact netdev matches and retain the shared-offdev fallback only for genuinely offloaded multi-port programs.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < e57f04194361574493e3e6cf0b9e9c69e4ae9791 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < 0dceda331180617aeeb22381e8480b37f18ba08b 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < 940b626854de200e6187777d42114727daca617c 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < bb375f3c5990e29851894f20ebc4b9dbc6676126 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 < 6db1ce73e9853f533eb7f413f14ba00f8ec6f80d
Linux / Linux
6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e57f04194361574493e3e6cf0b9e9c69e4ae9791 git.kernel.org: https://git.kernel.org/stable/c/0dceda331180617aeeb22381e8480b37f18ba08b git.kernel.org: https://git.kernel.org/stable/c/940b626854de200e6187777d42114727daca617c git.kernel.org: https://git.kernel.org/stable/c/bb375f3c5990e29851894f20ebc4b9dbc6676126 git.kernel.org: https://git.kernel.org/stable/c/6db1ce73e9853f533eb7f413f14ba00f8ec6f80d