CVE-2026-98378: bpf: Skip unsettled links in link iterator

Published Oct 9, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

bpf: Skip unsettled links in link iterator

bpflinkprime() inserts a link into linkidr before anoninodegetfile() succeeds and before bpflinksettle() publishes the ID in link->id. bpflinkbyid() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check.

If anoninodegetfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpflinkput() accesses freed memory.

Treat ID-zero entries as transient in bpflinkgetcurrornext(), just as bpflinkbyid() does.

BUG: KASAN: slab-use-after-free in bpflinkput Write of size 8 by task exp/384 Call Trace: bpflinkput kernel/bpf/syscall.c:3372 bpflinkseqnext kernel/bpf/linkiter.c:33 bpfseqread kernel/bpf/bpfiter.c:158 vfsread fs/readwrite.c:572 ksysread fs/readwrite.c:716 dosyscall64 arch/x86/entry/syscall64.c:84 entrySYSCALL64afterhwframe arch/x86/entry/entry64.S:121 Kernel panic - not syncing: KASAN: paniconwarn set ...

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 9, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
Description
Data Sourced
via NVD·08:16 AM
Description

Frequently Asked Questions

1

What conditions are required to trigger the use-after-free?

A link iterator must obtain a reference to a newly inserted link while that link still has ID zero, and anon_inode_getfile() must then fail during creation. The creator subsequently removes and frees the private link, leaving the iterator with a dangling reference.

2

What is the observable impact if the race occurs?

When the iterator later calls bpf_link_put(), it can access freed memory, producing a slab use-after-free. The supplied trace shows KASAN detecting the fault and a kernel panic when panic_on_warn is enabled.

3

How can I identify whether this issue has occurred on a system?

Look for KASAN reports identifying a slab-use-after-free in bpf_link_put(), with bpf_link_seq_next and bpf_seq_read in the call trace. A panic message stating that KASAN panic_on_warn is set may accompany the report.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203