Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98039— bpf: Require MEM_PERCPU for percpu kptr stores

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: BPF:要求 percpu kptr 存储必须包含 MEM_PERCPU 标记 函数将 视为 kptr 字段所允许的一类寄存器类型标志集合。对于 ,向该集合中添加 并不会要求源寄存器也携带此标志。因此,子集检查会同时接受通过 进行的普通分配以及指向 映射字段的已引用内核指针。 从该字段的加载操作始终带有 标记。消费者随后将存储的值视为 返回的 cookie:per-CPU 指针辅助函数会对其进行重定位,而映射销毁操作会选择 per-CPU 的释放路径。因此,普通分配可能导致

AI Predicted 7.8 Difficulty: Moderate EPSS 0.17% · P6

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux 36d8bdf75a93190e5669b9d1d95994e13e15ba1d< aaa9cf7707d1c5c0d2ca9d40c8b71652ac1c3c3f affected
36d8bdf75a93190e5669b9d1d95994e13e15ba1d< 0bdd6121c8dd5f1764efe701ce26bb8e15acb172 affected
36d8bdf75a93190e5669b9d1d95994e13e15ba1d< ad4ebae5dbc2d47b544aa54f03c12490065be08a affected
36d8bdf75a93190e5669b9d1d95994e13e15ba1d< 048029ba1c793f8cabc4ad5eea765da01903f8f1 affected
6.7 affected
< 6.7 unaffected
6.12.111≤ 6.12.* unaffected
6.18.53≤ 6.18.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98039

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bpf: Require MEM_PERCPU for percpu kptr stores
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Require MEM_PERCPU for percpu kptr stores map_kptr_match_type() treats perm_flags as the set of register type flags that a kptr field permits. Adding MEM_PERCPU to that set for BPF_KPTR_PERCPU does not require the source register to carry it, however. The subset test consequently accepts both a plain bpf_obj_new() allocation and a referenced kernel pointer into a __percpu_kptr map field. Loads from the field are always marked MEM_PERCPU. Consumers then treat the stored value as the cookie returned by bpf_percpu_obj_new(): per-CPU pointer helpers relocate it, and map teardown selects the per-CPU free path. A plain allocation can therefore provide an arbitrary kernel read/write, while a kernel pointer can be relocated into an invalid address or sent through a missing destructor. Require the source MEM_PERCPU flag to match the destination field kind. This preserves valid bpf_percpu_obj_new() stores and rejects both the program-BTF and kernel-BTF variants.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 36d8bdf75a93190e5669b9d1d95994e13e15ba1d ~ aaa9cf7707d1c5c0d2ca9d40c8b71652ac1c3c3f -
Linux Linux 6.7 -

II. Public POCs for CVE-2026-98039

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98039

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98039 (4)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-97941 7.8 HIGH mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-97937 7.8 HIGH ftrace: fork: Initialize function graph state before copy_exec_state()
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98039

No comments yet


Leave a comment