Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Skip unsettled links in link iterator

bpf_link_prime() inserts a link into link_idr before anon_inode_getfile()
succeeds and before bpf_link_settle() publishes the ID in link->id.
bpf_link_by_id() treats such an ID-zero link as unsettled, but the link
iterator takes a reference without this check.

If anon_inode_getfile() then fails, the creator removes the ID and frees
its still-private link directly. The iterator is left with a dangling
reference and its next bpf_link_put() accesses freed memory.

Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as
bpf_link_by_id() does.

BUG: KASAN: slab-use-after-free in bpf_link_put
Write of size 8 by task exp/384
Call Trace:
bpf_link_put kernel/bpf/syscall.c:3372
bpf_link_seq_next kernel/bpf/link_iter.c:33
bpf_seq_read kernel/bpf/bpf_iter.c:158
vfs_read fs/read_write.c:572
ksys_read fs/read_write.c:716
do_syscall_64 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121
Kernel panic - not syncing: KASAN: panic_on_warn set ...
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel's BPF subsystem, where an unsettled link is incorrectly handled by the link iterator. If an attacker creates a BPF link that is inserted into the IDR before it is settled, a subsequent call to bpf_link_put can dereference freed memory. This use‑after‑free can trigger a kernel panic. The weakness is a classic use‑after‑free flaw (CWE‑416).

Affected Systems

This bug affects all Linux kernel builds that do not incorporate the patch; the CPE identifier indicates the Linux kernel in general. No specific version range is listed, so any current kernel may be vulnerable unless the commit that introduced the fix is present. Users should verify their kernel version against the referenced commits.

Risk and Exploitability

The CVSS score is not provided and EPSS is unavailable, so quantitative risk data is missing. The issue is not listed in the CISA KEV catalog, indicating that no confirmed exploitation has been recorded. Based on the description, it is inferred that a local attacker who can create BPF link objects can trigger the flaw, making the attack vector likely local. The bug can cause a kernel panic (Denial of Service).

Generated by OpenCVE AI on October 9, 2026 at 09:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the patch for CVE-2026-98378
  • Reboot the system to load the updated kernel
  • Restart all services that rely on eBPF to ensure they use the corrected kernel functions

Generated by OpenCVE AI on October 9, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Skip unsettled links in link iterator bpf_link_prime() inserts a link into link_idr before anon_inode_getfile() succeeds and before bpf_link_settle() publishes the ID in link->id. bpf_link_by_id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check. If anon_inode_getfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpf_link_put() accesses freed memory. Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as bpf_link_by_id() does. BUG: KASAN: slab-use-after-free in bpf_link_put Write of size 8 by task exp/384 Call Trace: bpf_link_put kernel/bpf/syscall.c:3372 bpf_link_seq_next kernel/bpf/link_iter.c:33 bpf_seq_read kernel/bpf/bpf_iter.c:158 vfs_read fs/read_write.c:572 ksys_read fs/read_write.c:716 do_syscall_64 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121 Kernel panic - not syncing: KASAN: panic_on_warn set ...
Title bpf: Skip unsettled links in link iterator
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:18.626Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98378

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:56.123

Modified: 2026-10-09T08:16:56.123

Link: CVE-2026-98378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T10:00:05Z

Weaknesses