CVE-2026-98378: bpf: Skip unsettled links in link iterator
In the Linux kernel, the following vulnerability has been resolved:
bpf: Skip unsettled links in link iterator
bpflinkprime() inserts a link into linkidr before anoninodegetfile() succeeds and before bpflinksettle() publishes the ID in link->id. bpflinkbyid() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check.
If anoninodegetfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpflinkput() accesses freed memory.
Treat ID-zero entries as transient in bpflinkgetcurrornext(), just as bpflinkbyid() does.
BUG: KASAN: slab-use-after-free in bpflinkput Write of size 8 by task exp/384 Call Trace: bpflinkput kernel/bpf/syscall.c:3372 bpflinkseqnext kernel/bpf/linkiter.c:33 bpfseqread kernel/bpf/bpfiter.c:158 vfsread fs/readwrite.c:572 ksysread fs/readwrite.c:716 dosyscall64 arch/x86/entry/syscall64.c:84 entrySYSCALL64afterhwframe arch/x86/entry/entry64.S:121 Kernel panic - not syncing: KASAN: paniconwarn set ...
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the use-after-free?
A link iterator must obtain a reference to a newly inserted link while that link still has ID zero, and anon_inode_getfile() must then fail during creation. The creator subsequently removes and frees the private link, leaving the iterator with a dangling reference.
What is the observable impact if the race occurs?
When the iterator later calls bpf_link_put(), it can access freed memory, producing a slab use-after-free. The supplied trace shows KASAN detecting the fault and a kernel panic when panic_on_warn is enabled.
How can I identify whether this issue has occurred on a system?
Look for KASAN reports identifying a slab-use-after-free in bpf_link_put(), with bpf_link_seq_next and bpf_seq_read in the call trace. A panic message stating that KASAN panic_on_warn is set may accompany the report.