CVE-2026-98382: bpf: Reject dev-bound-only programs on other devices
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject dev-bound-only programs on other devices
bpfoffloaddevmatch() falls back to comparing offdev pointers after an exact netdev mismatch. Bound-only programs normally have NULL offdevs, so unrelated netdevs compare equal. A bound-only program on an offload-registered netdev can instead inherit a real offdev and match a sibling port. With CAPBPF and CAPNETADMIN, a caller can use bpf(BPFLINKCREATE) with a different target ifindex to run metadata kfuncs specialized for the bound driver on the target driver's xdpbuff. Running a veth-bound program on tun reads beyond tun's bare stack xdpbuff as a vethxdpbuff.
Oops: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:vethxdprxtimestamp (drivers/net/veth.c:1673) Call Trace: ... tunbuildskb (drivers/net/tun.c:1739) tungetuser (drivers/net/tun.c:1856) tunchrwriteiter (drivers/net/tun.c:2091) vfswrite (fs/readwrite.c:595 fs/readwrite.c:687) ksyswrite (fs/readwrite.c:739) dosyscall64 (arch/x86/entry/syscall64.c:84) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:121) Kernel panic - not syncing: Fatal exception in interrupt
Restrict non-offloaded programs to exact netdev matches and retain the shared-offdev fallback only for genuinely offloaded multi-port programs.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires a caller with both CAP_BPF and CAP_NET_ADMIN. The caller must be able to create a BPF link using BPF_LINK_CREATE and specify a different target interface index.
What configurations are exposed?
The issue involves device-bound-only BPF programs on an offload-registered network device that can incorrectly match a sibling port. The described crash occurs when a veth-bound program is run against a tun device, causing driver-specific metadata handling to interpret tun's xdp_buff as a veth_xdp_buff.
What is the likely impact?
The described outcome is a kernel fault, including a general protection fault and KASAN null-pointer dereference, when the mismatched program accesses device-specific XDP metadata. This indicates a local denial-of-service condition through a kernel crash.