CVE-2026-98382

Source
https://cve.org/CVERecord?id=CVE-2026-98382
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98382.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98382
Downstream
Published
2026-10-09T07:34:21Z
Modified
2026-10-11T02:46:56Z
Summary
bpf: Reject dev-bound-only programs on other devices
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject dev-bound-only programs on other devices

__bpf_offload_dev_match() falls back to comparing offdev pointers after an exact netdev mismatch. Bound-only programs normally have NULL offdevs, so unrelated netdevs compare equal. A bound-only program on an offload-registered netdev can instead inherit a real offdev and match a sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs specialized for the bound driver on the target driver's xdp_buff. Running a veth-bound program on tun reads beyond tun's bare stack xdp_buff as a veth_xdp_buff.

Oops: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673) Call Trace: ... tun_build_skb (drivers/net/tun.c:1739) tun_get_user (drivers/net/tun.c:1856) tun_chr_write_iter (drivers/net/tun.c:2091) vfs_write (fs/read_write.c:595 fs/read_write.c:687) ksys_write (fs/read_write.c:739) do_syscall_64 (arch/x86/entry/syscall_64.c:84) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Kernel panic - not syncing: Fatal exception in interrupt

Restrict non-offloaded programs to exact netdev matches and retain the shared-offdev fallback only for genuinely offloaded multi-port programs.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98382.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2b3486bc2d237ec345b3942b7be5deabf8c8fed1
Fixed
e57f04194361574493e3e6cf0b9e9c69e4ae9791
Fixed
0dceda331180617aeeb22381e8480b37f18ba08b
Fixed
940b626854de200e6187777d42114727daca617c
Fixed
bb375f3c5990e29851894f20ebc4b9dbc6676126
Fixed
6db1ce73e9853f533eb7f413f14ba00f8ec6f80d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98382.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.55
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98382.json"