Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL

An LWT_SEG6LOCAL program can invalidate its cached SRH with
bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter
may reallocate skb->head, leaving the per-CPU SRH pointer dangling.
Post-program SRH validation then writes through that pointer.

Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier
rejects this unsafe helper combination. Other LWT program types continue
to expose the helper through lwt_out_func_proto().
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Kernel Memory Corruption
Action: Apply Patch
AI Analysis

Impact

A Linux kernel BPF helper combination allows a LWT_SEG6LOCAL program to invalidate its cached SRH pointer by calling bpf_lwt_seg6_adjust_srh() and subsequently invoke bpf_skb_pull_data(). The helper may reallocate skb->head, leaving the per‑CPU SRH pointer dangling. When the program ends, post‑program SRH validation writes through the stale pointer, resulting in memory corruption inside the kernel. This can compromise the integrity of kernel memory and potentially lead to local privilege escalation or denial of service if the attacker can load such a program.

Affected Systems

All Linux kernels that provide support for LWT_SEG6LOCAL BPF programs are impacted. The vulnerability is specific to the kernel’s BPF verifier logic; version information is not provided, so any kernel before the patch that allows LWT_SEG6LOCAL programs and exposes the helper combination is considered vulnerable. Systems running updated kernels where the verifier rejects the helper are no longer affected.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, which suggests limited publicly reported exploitation. However, the nature of the flaw—kernel memory corruption—implies a high potential severity if an attacker can load a LWT_SEG6LOCAL program. The attack requires local privileged execution to load the program, so the vector is internal. In environments where BPF program loading is possible by non‑root users, the risk increases. Absent an official CVSS score, the risk is judged as significant because the vulnerability can lead to compromise of kernel memory.

Generated by OpenCVE AI on October 9, 2026 at 09:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch that restricts bpf_skb_pull_data() for LWT_SEG6LOCAL programs
  • If an immediate kernel update is not feasible, disable BPF program loading for LWT_SEG6LOCAL or restrict it to privileged users with bastion controls
  • Verify that the BPF verifier configuration rejects use of bpf_skb_pull_data() in LWT_SEG6LOCAL programs by inspecting kernel logs or BPF audit logs

Generated by OpenCVE AI on October 9, 2026 at 09:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL An LWT_SEG6LOCAL program can invalidate its cached SRH with bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter may reallocate skb->head, leaving the per-CPU SRH pointer dangling. Post-program SRH validation then writes through that pointer. Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier rejects this unsafe helper combination. Other LWT program types continue to expose the helper through lwt_out_func_proto().
Title bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:22.408Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98383

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:56.800

Modified: 2026-10-09T08:16:56.800

Link: CVE-2026-98383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:30:03Z

Weaknesses