Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject dev-bound-only programs on other devices

__bpf_offload_dev_match() falls back to comparing offdev pointers after an
exact netdev mismatch. Bound-only programs normally have NULL offdevs, so
unrelated netdevs compare equal. A bound-only program on an
offload-registered netdev can instead inherit a real offdev and match a
sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use
bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs
specialized for the bound driver on the target driver's xdp_buff. Running a
veth-bound program on tun reads beyond tun's bare stack xdp_buff as a
veth_xdp_buff.

Oops: general protection fault, probably for non-canonical address
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673)
Call Trace:
...
tun_build_skb (drivers/net/tun.c:1739)
tun_get_user (drivers/net/tun.c:1856)
tun_chr_write_iter (drivers/net/tun.c:2091)
vfs_write (fs/read_write.c:595 fs/read_write.c:687)
ksys_write (fs/read_write.c:739)
do_syscall_64 (arch/x86/entry/syscall_64.c:84)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt

Restrict non-offloaded programs to exact netdev matches and retain the
shared-offdev fallback only for genuinely offloaded multi-port programs.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service via kernel crash
Action: Patch immediately
AI Analysis

Impact

A flaw in the Linux kernel BPF subsystem allows a device-bound BPF program to be registered or executed on a different network device when the internal developer match function mis‑evaluates net device pointers. The incorrect comparison lets a privileged caller (CAP_BPF + CAP_NET_ADMIN) create a BPF link with a mismatched target, causing the kernel to dereference a NULL or invalid pointer and trigger a general protection fault. The result is a kernel panic, effectively denying service for the affected host.

Affected Systems

Linux kernel builds prior to the patch that implements this fix are vulnerable. The issue applies to all architectures where the BPF MDP code is compiled, and is triggered when a user with capability to create BPF links attaches a program to an offload‑registered net device that is not its own device. Specific kernel versions are not enumerated in the advisory, but any kernel that includes the unpatched __bpf_offload_dev_match logic is affected.

Risk and Exploitability

The CVSS score is not listed in the input and EPSS data is not available, but the vulnerability requires local privileged execution. Once a CAP_BPF or CAP_NET_ADMIN user injects a test program, they can force a kernel crash and cause a denial of service on the host. The vulnerability is listed in no CISA KEV catalog and currently has no known public exploit, however the high impact and exploitability for privileged users warrant prompt remediation.

Generated by OpenCVE AI on October 9, 2026 at 10:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the patch referenced in the advisory, which restores proper dev‑match logic and prevents offload fall‑back for non‑bound programs.
  • If an immediate update is not possible, isolate untrusted processes from CAP_BPF and CAP_NET_ADMIN capabilities, ensuring only trusted users can create BPF links.
  • For environments that rely on offloaded BPF programs, verify that the offload register and dev‑match configuration are legitimate and not exposed to untrusted code; consider disabling offload if not required.

Generated by OpenCVE AI on October 9, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Reject dev-bound-only programs on other devices __bpf_offload_dev_match() falls back to comparing offdev pointers after an exact netdev mismatch. Bound-only programs normally have NULL offdevs, so unrelated netdevs compare equal. A bound-only program on an offload-registered netdev can instead inherit a real offdev and match a sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs specialized for the bound driver on the target driver's xdp_buff. Running a veth-bound program on tun reads beyond tun's bare stack xdp_buff as a veth_xdp_buff. Oops: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673) Call Trace: ... tun_build_skb (drivers/net/tun.c:1739) tun_get_user (drivers/net/tun.c:1856) tun_chr_write_iter (drivers/net/tun.c:2091) vfs_write (fs/read_write.c:595 fs/read_write.c:687) ksys_write (fs/read_write.c:739) do_syscall_64 (arch/x86/entry/syscall_64.c:84) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Kernel panic - not syncing: Fatal exception in interrupt Restrict non-offloaded programs to exact netdev matches and retain the shared-offdev fallback only for genuinely offloaded multi-port programs.
Title bpf: Reject dev-bound-only programs on other devices
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:21.718Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98382

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:56.680

Modified: 2026-10-09T08:16:56.680

Link: CVE-2026-98382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T10:30:05Z

Weaknesses