Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98383— bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: BPF:禁止 LWT_SEG6LOCAL 程序调用 bpf_skb_pull_data() LWT_SEG6LOCAL 程序可以通过调用 bpf_lwt_seg6_adjust_srh() 使其缓存的 SRH(Seg6 Route Header)失效,随后再调用 bpf_skb_pull_data()。后者可能会重新分配 skb->head,导致每 CPU 变量的 SRH 指针变为悬空指针(dangling pointer)。在程序执行结束后进行 SRH 验证时,会通过

AI Predicted 7.8 Difficulty: Hard

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98383

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL An LWT_SEG6LOCAL program can invalidate its cached SRH with bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter may reallocate skb->head, leaving the per-CPU SRH pointer dangling. Post-program SRH validation then writes through that pointer. Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier rejects this unsafe helper combination. Other LWT program types continue to expose the helper through lwt_out_func_proto().
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 004d4b274e2a1a895a0e5dc66158b90a7d463d44 ~ 0f38472a2aa8704a6b514c0dfa9c32f3672b8f32 -
Linux Linux 4.18 -

II. Public POCs for CVE-2026-98383

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98383

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98383 (8)

Same Patch Batch · Linux · 2026-10-09 · 10 CVEs total

CVE-2026-98384 bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
CVE-2026-98382 bpf: Reject dev-bound-only programs on other devices
CVE-2026-98381 veth: manage XDP program pointers during channel resize
CVE-2026-98380 net/sched: reject IDR error pointers when deleting actions
CVE-2026-98378 bpf: Skip unsettled links in link iterator
CVE-2026-98379 netfilter: ip6t_rpfilter: reject routes without inet6_dev
CVE-2026-98377 vlan: require the MAC header to be present in __vlan_insert_inner_tag()
CVE-2026-98376 bpf: Use array_map_meta_equal for percpu array inner map replacement
CVE-2026-98375 xen/netfront: drop RX packets with a short Ethernet header

IV. Related Vulnerabilities

V. Comments for CVE-2026-98383

No comments yet


Leave a comment