Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98381— veth: manage XDP program pointers during channel resize

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: veth:在调整通道大小时管理 XDP 程序指针 函数在移除接收队列(RX queues)时会释放 XDP 相关资源,但未清除 指针。如果随后将该 XDP 程序分离或替换,在调用 释放旧程序后,这些队列仍保留指向已释放内存的旧指针。此后若增加通道数量以重新启用 NAPI 机制,则可能执行已释放的 XDP 程序,从而导致严重错误。 BUG: 无法处理页错误,地址为:ffffc90000256048 Oops: Oops: 0000 [#1] SMP KASAN NOPTI

AI Predicted 7.8 Difficulty: Easy EPSS 0.16% · P5

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7< 7a8e143109ff2736dc79e41dcd55af7ceab7520a affected
4752eeb3d891c27905a8fdf4d80e899c0efd4ec7< 1a5c5b9c64ba5f39dba55da6e12561ca56eeb758 affected
4752eeb3d891c27905a8fdf4d80e899c0efd4ec7< f0e8dba8c224981e53c792c6b3dbb7604fb2c2c6 affected
4752eeb3d891c27905a8fdf4d80e899c0efd4ec7< 3c10a5dd0d38f506f671dbb59e9d0ee4c72076f9 affected
4752eeb3d891c27905a8fdf4d80e899c0efd4ec7< 25bb7c36225220d30f404d7e29d2e052bc5f4b99 affected
4752eeb3d891c27905a8fdf4d80e899c0efd4ec7< 43f6b647f209591b1e3f726bb16b8dcba6b95908 affected
4752eeb3d891c27905a8fdf4d80e899c0efd4ec7< 7104a370714346b667712913dc16abf14bbc97ed affected
5.15 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98381

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
veth: manage XDP program pointers during channel resize
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: veth: manage XDP program pointers during channel resize veth_set_channels() tears down XDP resources for removed RX queues without clearing rq->xdp_prog. If the program is then detached or replaced, those queues keep the old pointer after bpf_prog_put(). A later channel increase can re-enable NAPI and run the freed program. BUG: unable to handle page fault for address: ffffc90000256048 Oops: Oops: 0000 [#1] SMP KASAN NOPTI RIP: veth_xdp_rcv_skb (include/linux/filter.h:779 include/net/xdp.h:696 drivers/net/veth.c:820) Call Trace: veth_xdp_rcv (drivers/net/veth.c:941) veth_poll (drivers/net/veth.c:986) __napi_poll (net/core/dev.c:7787) net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007) handle_softirqs (kernel/softirq.c:645) Kernel panic - not syncing: Fatal exception in interrupt
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 ~ 7a8e143109ff2736dc79e41dcd55af7ceab7520a -
Linux Linux 5.15 -

II. Public POCs for CVE-2026-98381

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98381

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98381 (7)

Same Patch Batch · Linux · 2026-10-09 · 10 CVEs total

CVE-2026-98384 bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
CVE-2026-98383 bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
CVE-2026-98382 bpf: Reject dev-bound-only programs on other devices
CVE-2026-98380 net/sched: reject IDR error pointers when deleting actions
CVE-2026-98378 bpf: Skip unsettled links in link iterator
CVE-2026-98379 netfilter: ip6t_rpfilter: reject routes without inet6_dev
CVE-2026-98377 vlan: require the MAC header to be present in __vlan_insert_inner_tag()
CVE-2026-98376 bpf: Use array_map_meta_equal for percpu array inner map replacement
CVE-2026-98375 xen/netfront: drop RX packets with a short Ethernet header

IV. Related Vulnerabilities

V. Comments for CVE-2026-98381

No comments yet


Leave a comment