CVE-2026-98376: bpf: Use array_map_meta_equal for percpu array inner map replacement
In the Linux kernel, the following vulnerability has been resolved:
bpf: Use arraymapmetaequal for percpu array inner map replacement
percpuarraymapops.mapmetaequal points to the generic bpfmapmetaequal(), which does not compare maxentries. When a percpu array serves as an inner map, replacing it with one that has fewer maxentries bypasses the check. Since percpuarraymapgenlookup() inlines the original template's indexmask as a JIT immediate, a lookup on the replacement map can access pptrs[] out of bounds.
Point percpuarraymapops.mapmetaequal to arraymapmetaequal(), which already enforces the maxentries equality check.
Add a selftest to verify that replacing a percpu array inner map with a differently-sized one is rejected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Add a selftest verifying that replacing a percpu array inner map with a differently sized map is rejected.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The affected scenario requires a per-CPU array map to be used as an inner map and then replaced with another per-CPU array map that has fewer max_entries. The issue is tied to JIT-generated lookup code retaining the original inner-map template's index_mask.
What must an attacker or triggering workload be able to do?
It must be able to replace a per-CPU array inner map with a smaller one after the original map template has been used. This bypasses the metadata check because the generic comparison did not verify max_entries.
What happens if the vulnerable replacement is accepted?
A lookup against the replacement map can access the pptrs[] array out of bounds, because the generated lookup code uses the original template's index_mask as an immediate value.
What is the remediation?
Apply the Linux kernel fix that changes per-CPU array map metadata comparison to array_map_meta_equal(). That comparison enforces equal max_entries values and rejects differently sized replacement maps.