CVE-2026-98382: bpf: Reject dev-bound-only programs on other devices

Published Oct 9, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject dev-bound-only programs on other devices

bpfoffloaddevmatch() falls back to comparing offdev pointers after an exact netdev mismatch. Bound-only programs normally have NULL offdevs, so unrelated netdevs compare equal. A bound-only program on an offload-registered netdev can instead inherit a real offdev and match a sibling port. With CAPBPF and CAPNETADMIN, a caller can use bpf(BPFLINKCREATE) with a different target ifindex to run metadata kfuncs specialized for the bound driver on the target driver's xdpbuff. Running a veth-bound program on tun reads beyond tun's bare stack xdpbuff as a vethxdpbuff.

Oops: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:vethxdprxtimestamp (drivers/net/veth.c:1673) Call Trace: ... tunbuildskb (drivers/net/tun.c:1739) tungetuser (drivers/net/tun.c:1856) tunchrwriteiter (drivers/net/tun.c:2091) vfswrite (fs/readwrite.c:595 fs/readwrite.c:687) ksyswrite (fs/readwrite.c:739) dosyscall64 (arch/x86/entry/syscall64.c:84) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:121) Kernel panic - not syncing: Fatal exception in interrupt

Restrict non-offloaded programs to exact netdev matches and retain the shared-offdev fallback only for genuinely offloaded multi-port programs.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 9, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
Description
Data Sourced
via NVD·08:16 AM
Description

Frequently Asked Questions

1

Who can exploit this issue?

Exploitation requires a caller with both CAP_BPF and CAP_NET_ADMIN. The caller must be able to create a BPF link using BPF_LINK_CREATE and specify a different target interface index.

2

What configurations are exposed?

The issue involves device-bound-only BPF programs on an offload-registered network device that can incorrectly match a sibling port. The described crash occurs when a veth-bound program is run against a tun device, causing driver-specific metadata handling to interpret tun's xdp_buff as a veth_xdp_buff.

3

What is the likely impact?

The described outcome is a kernel fault, including a general protection fault and KASAN null-pointer dereference, when the mismatched program accesses device-specific XDP metadata. This indicates a local denial-of-service condition through a kernel crash.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203