Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98376— bpf: Use array_map_meta_equal for percpu array inner map replacement

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已被修复: bpf:在使用 percpu 数组内部地图替换时,使用 指向的是通用的 函数,该函数未比较 字段。当 percpu 数组作为内部地图(inner map)使用时,若用具有更小 值的地图进行替换,可绕过该检查。由于 会将原始模板的 内联为 JIT 立即数,对替换后的地图进行查找操作可能导致越界访问 数组。 将 指向 ,后者已强制执行 相等性检查。 新增一项自测(selftest)用例,验证当尝试将 percpu 数组内部地图替换为不同大小的地图时,系统会正确拒绝该操作。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.15% · P3

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98376

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bpf: Use array_map_meta_equal for percpu array inner map replacement
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Use array_map_meta_equal for percpu array inner map replacement percpu_array_map_ops.map_meta_equal points to the generic bpf_map_meta_equal(), which does not compare max_entries. When a percpu array serves as an inner map, replacing it with one that has fewer max_entries bypasses the check. Since percpu_array_map_gen_lookup() inlines the original template's index_mask as a JIT immediate, a lookup on the replacement map can access pptrs[] out of bounds. Point percpu_array_map_ops.map_meta_equal to array_map_meta_equal(), which already enforces the max_entries equality check. Add a selftest to verify that replacing a percpu array inner map with a differently-sized one is rejected.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux db69718b8efac802c7cc20d5a6c7dfc913f99c43 ~ 593980175389a05793f6060aa20e626330960395 -
Linux Linux 6.10 -

II. Public POCs for CVE-2026-98376

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98376

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98376 (1)

Same Patch Batch · Linux · 2026-10-09 · 10 CVEs total

CVE-2026-98384 bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
CVE-2026-98383 bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
CVE-2026-98382 bpf: Reject dev-bound-only programs on other devices
CVE-2026-98381 veth: manage XDP program pointers during channel resize
CVE-2026-98380 net/sched: reject IDR error pointers when deleting actions
CVE-2026-98378 bpf: Skip unsettled links in link iterator
CVE-2026-98379 netfilter: ip6t_rpfilter: reject routes without inet6_dev
CVE-2026-98377 vlan: require the MAC header to be present in __vlan_insert_inner_tag()
CVE-2026-98375 xen/netfront: drop RX packets with a short Ethernet header

IV. Related Vulnerabilities

V. Comments for CVE-2026-98376

No comments yet


Leave a comment