CVE-2026-98085: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge Nicholas Carlini reported a bug in precision backtracking mechanism for BPF_LD | BPF_{IND,ABS} instructions. These instructions are modelled as two branches: - fallthrough; - implicit exit from current subprogram. The implicit exit case was not handled by the backtrack_insn() function. When backtracking such a path backtrack_insn() did not call bt_subprog_enter(), which meant that backtracking continued manipulating precision marks in a caller frame, while looking at instructions in a callee frame. This lead to segmentation faults during verification (see the selftest), or unsound state pruning.

Affected products

  • Linux Linux: from 5.10.265, before 5.11 (fixed in 5.11); from 5.15.216, before 5.16 (fixed in 5.16); from 6.1.183, before 6.2 (fixed in 6.2); from 6.6.148, before 6.7 (fixed in 6.7); from 6.12.101, before 6.13 (fixed in 6.13); from 6.18.42, before 6.19 (fixed in 6.19); …

Published 2026-09-25. Last modified 2026-09-30.