← All Advisories

CVE-2026-98150

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98150

Key Details

CVECVE-2026-98150
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix BPF_F_CPU validation for sparse CPU IDs

BPF_F_CPU stores the target CPU ID in the upper 32 bits of the map

operation flags. bpf_map_check_op_flags() currently compares that ID

with num_possible_cpus(), which is the number of possible CPUs rather

than a bound on CPU IDs.

On an arm64 QEMU guest with a CPU device-tree hole, the possible CPU

mask was 0,2-3. A userspace program using raw bpf() syscalls creates

a BPF_MAP_TYPE_PERCPU_ARRAY and performs update and lookup operations

for each CPU by setting BPF_F_CPU and the CPU ID in the flags.

With the old check, CPU 1 is incorrectly accepted while valid CPU 3 is

rejected with -ERANGE. The CPU 1 update then reaches the per-CPU map

access path and triggers:

Unable to handle kernel paging request at virtual address ...

pc : __pi_memcpy_generic+0x5c/0x22c

lr : bpf_percpu_array_update+0x2dc/0x2e8

Call trace:

__pi_memcpy_generic

bpf_map_update_value

map_update_elem

__sys_bpf

Check the CPU ID against nr_cpu_ids and cpu_possible() instead. This

rejects CPU IDs outside the valid range and CPUs absent from the

possible mask, while allowing valid sparse CPU IDs. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98150
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98150