CVE-2026-98383

Source
https://cve.org/CVERecord?id=CVE-2026-98383
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98383.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98383
Downstream
Published
2026-10-09T07:34:22Z
Modified
2026-10-11T02:46:33Z
Summary
bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL

An LWT_SEG6LOCAL program can invalidate its cached SRH with bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter may reallocate skb->head, leaving the per-CPU SRH pointer dangling. Post-program SRH validation then writes through that pointer.

Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier rejects this unsafe helper combination. Other LWT program types continue to expose the helper through lwt_out_func_proto().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98383.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
004d4b274e2a1a895a0e5dc66158b90a7d463d44
Fixed
0f38472a2aa8704a6b514c0dfa9c32f3672b8f32
Fixed
cae8674489f26edf7553fdd660599466cbb4c32f
Fixed
9f9e57b5a3a033f95f49ef9d541340cdbcb80abb
Fixed
df0072be6fc373cb22f9ea854d458b04e32a03cf
Fixed
b9bb0e735460751b620156f800a4279a28573392
Fixed
37b18688cd18fd86d2f35c212df1611862a26cd5
Fixed
fca71ead7a20290af1e2046983eeafae43d21af1
Fixed
e4a62833adff6ef0fe7c0b90393204fe3c26b5c5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98383.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.18.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.55
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98383.json"