CVE-2026-98075

Source
https://cve.org/CVERecord?id=CVE-2026-98075
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98075.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98075
Downstream
Published
2026-09-25T10:24:14Z
Modified
2026-09-26T03:48:32Z
Summary
bpf: reject BPF_PSEUDO_FUNC reference to the main program
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: reject BPF_PSEUDO_FUNC reference to the main program

fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real function addresses. This function is invoked from bpf_jit_subprogs() only when env->subprog_cnt > 1. Meaning that for any program like below:

int main(void *ctx) { void *ptr = main; ... bpf_timer_set_callback(..., ptr); ... }

The 'ptr' won't be ever converted to contain an address. In combination with e.g. bpf_timer_set_callback() this would lead to a function call at a bogus address.

Instead of complicating the implementation, just assume that no useful program needs main to be a sync or async callback and reject BPF_PSEUDO_FUNC loads for the main subprogram.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98075.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
69c087ba6225b574afb6e505b72cb75242a3d844
Fixed
118212417ba0120d99f84154799f8880f07411f4
Fixed
d6c39774ae093c9f7009cc4ae918f18fc1af7ae7
Fixed
92f0bd0e2b632c6565ac2214a4d7d2ed37e5b9f6
Fixed
374b2c5561db80fcdd7cdce44af37a49416f61c7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98075.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98075.json"