Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98378— bpf: Skip unsettled links in link iterator

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到解决: bpf: 在链接迭代器中跳过未稳定的链接 在 成功之前,以及在 将 ID 发布到 之前,就将一个链接插入到了 中。 将此类 ID 为零的链接视为未稳定状态,但链接迭代器在未进行此检查的情况下获取了引用。 如果随后 失败,创建者会移除该 ID 并直接释放仍处于私有状态的链接。此时迭代器仍持有一个悬空引用,其随后的 调用将访问已释放的内存。 在 中,应将 ID 为零的条目视为瞬态条目,就像 所做的那样。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.16% · P5

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8< 68930f8d40ab4c10ca3b019f076136758fd100a8 affected
9f88361273082825d9f0d13a543d49f9fa0d44a8< c251ed48bd9063cf7de6049421e78b6de989060f affected
9f88361273082825d9f0d13a543d49f9fa0d44a8< 798a61edbc436cacdb659927d067368eeb1e30e2 affected
9f88361273082825d9f0d13a543d49f9fa0d44a8< 6e271f093d15d323f42de26f66556af53fa8e19f affected
9f88361273082825d9f0d13a543d49f9fa0d44a8< 87ce4b53b7436b50fc984f0a6afaf77f68ac5573 affected
9f88361273082825d9f0d13a543d49f9fa0d44a8< 50e80e2bb5e2be8515205b9c496b9640ddefa434 affected
5.19 affected
< 5.19 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98378

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bpf: Skip unsettled links in link iterator
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Skip unsettled links in link iterator bpf_link_prime() inserts a link into link_idr before anon_inode_getfile() succeeds and before bpf_link_settle() publishes the ID in link->id. bpf_link_by_id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check. If anon_inode_getfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpf_link_put() accesses freed memory. Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as bpf_link_by_id() does. BUG: KASAN: slab-use-after-free in bpf_link_put Write of size 8 by task exp/384 Call Trace: bpf_link_put kernel/bpf/syscall.c:3372 bpf_link_seq_next kernel/bpf/link_iter.c:33 bpf_seq_read kernel/bpf/bpf_iter.c:158 vfs_read fs/read_write.c:572 ksys_read fs/read_write.c:716 do_syscall_64 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121 Kernel panic - not syncing: KASAN: panic_on_warn set ...
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 9f88361273082825d9f0d13a543d49f9fa0d44a8 ~ 68930f8d40ab4c10ca3b019f076136758fd100a8 -
Linux Linux 5.19 -

II. Public POCs for CVE-2026-98378

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98378

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98378 (6)

Same Patch Batch · Linux · 2026-10-09 · 10 CVEs total

CVE-2026-98384 bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
CVE-2026-98383 bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
CVE-2026-98382 bpf: Reject dev-bound-only programs on other devices
CVE-2026-98381 veth: manage XDP program pointers during channel resize
CVE-2026-98380 net/sched: reject IDR error pointers when deleting actions
CVE-2026-98379 netfilter: ip6t_rpfilter: reject routes without inet6_dev
CVE-2026-98377 vlan: require the MAC header to be present in __vlan_insert_inner_tag()
CVE-2026-98376 bpf: Use array_map_meta_equal for percpu array inner map replacement
CVE-2026-98375 xen/netfront: drop RX packets with a short Ethernet header

IV. Related Vulnerabilities

V. Comments for CVE-2026-98378

No comments yet


Leave a comment