Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Use array_map_meta_equal for percpu array inner map replacement

percpu_array_map_ops.map_meta_equal points to the generic
bpf_map_meta_equal(), which does not compare max_entries. When a
percpu array serves as an inner map, replacing it with one that has
fewer max_entries bypasses the check. Since percpu_array_map_gen_lookup()
inlines the original template's index_mask as a JIT immediate, a lookup
on the replacement map can access pptrs[] out of bounds.

Point percpu_array_map_ops.map_meta_equal to array_map_meta_equal(),
which already enforces the max_entries equality check.

Add a selftest to verify that replacing a percpu array inner map with
a differently-sized one is rejected.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Kernel Out-of-Bounds Memory Access
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Linux kernel's BPF implementation allows an attacker to replace a per‑cpu array inner map with a smaller one. The system fails to enforce the same maximum entry count, enabling a lookup to read beyond the bounds of an array. This out‑of‑bounds read can corrupt kernel memory and potentially lead to privilege escalation or system instability.

Affected Systems

The vulnerability is present in all Linux kernel distributions, as the affected component is part of the core Linux kernel code. No specific vendor or vendor‑specific product versioning information is provided, but all systems running a kernel version that has not yet applied the patch are affected.

Risk and Exploitability

The CVSS score is not provided, but the lack of an EPSS score and absence from the CISA KEV catalog suggest limited publicly known exploitation. The vulnerability requires kernel‑level BPF map manipulation and therefore a suitable attacker already with limited local access to load or modify BPF programs. Once the vulnerability is triggered, it can result in kernel panic or privilege escalation, making it a high‑risk condition for systems that expose BPF interfaces to untrusted users or code.

Generated by OpenCVE AI on October 9, 2026 at 09:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the patch for the BPF per‑cpu array inner map replacement.
  • Verify that the kernel’s BPF map_meta_equal function points to array_map_meta_equal by inspecting the kernel configuration or source. If the risk remains, revert to a kernel release before the vulnerability was introduced.
  • If an immediate kernel upgrade is not possible, disable BPF or limit BPF capabilities via a security module such as SELinux or AppArmor.

Generated by OpenCVE AI on October 9, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Use array_map_meta_equal for percpu array inner map replacement percpu_array_map_ops.map_meta_equal points to the generic bpf_map_meta_equal(), which does not compare max_entries. When a percpu array serves as an inner map, replacing it with one that has fewer max_entries bypasses the check. Since percpu_array_map_gen_lookup() inlines the original template's index_mask as a JIT immediate, a lookup on the replacement map can access pptrs[] out of bounds. Point percpu_array_map_ops.map_meta_equal to array_map_meta_equal(), which already enforces the max_entries equality check. Add a selftest to verify that replacing a percpu array inner map with a differently-sized one is rejected.
Title bpf: Use array_map_meta_equal for percpu array inner map replacement
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:17.043Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98376

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:55.910

Modified: 2026-10-09T08:16:55.910

Link: CVE-2026-98376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T10:00:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer