CVE-2026-98378

Source
https://cve.org/CVERecord?id=CVE-2026-98378
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98378.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98378
Downstream
Published
2026-10-09T07:34:18Z
Modified
2026-10-11T02:47:29Z
Summary
bpf: Skip unsettled links in link iterator
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Skip unsettled links in link iterator

bpf_link_prime() inserts a link into link_idr before anon_inode_getfile() succeeds and before bpf_link_settle() publishes the ID in link->id. bpf_link_by_id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check.

If anon_inode_getfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpf_link_put() accesses freed memory.

Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as bpf_link_by_id() does.

BUG: KASAN: slab-use-after-free in bpf_link_put Write of size 8 by task exp/384 Call Trace: bpf_link_put kernel/bpf/syscall.c:3372 bpf_link_seq_next kernel/bpf/link_iter.c:33 bpf_seq_read kernel/bpf/bpf_iter.c:158 vfs_read fs/read_write.c:572 ksys_read fs/read_write.c:716 do_syscall_64 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121 Kernel panic - not syncing: KASAN: panic_on_warn set ...

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98378.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9f88361273082825d9f0d13a543d49f9fa0d44a8
Fixed
68930f8d40ab4c10ca3b019f076136758fd100a8
Fixed
c251ed48bd9063cf7de6049421e78b6de989060f
Fixed
798a61edbc436cacdb659927d067368eeb1e30e2
Fixed
6e271f093d15d323f42de26f66556af53fa8e19f
Fixed
87ce4b53b7436b50fc984f0a6afaf77f68ac5573
Fixed
50e80e2bb5e2be8515205b9c496b9640ddefa434

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98378.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.55
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98378.json"