{"id":"CVE-2026-98085","published":"2026-09-25T11:17:38.087","lastModified":"2026-09-25T11:17:38.087","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge\n\nNicholas Carlini reported a bug in precision backtracking mechanism\nfor BPF_LD | BPF_{IND,ABS} instructions. These instructions are\nmodelled as two branches:\n- fallthrough;\n- implicit exit from current subprogram.\n\nThe implicit exit case was not handled by the backtrack_insn()\nfunction. When backtracking such a path backtrack_insn() did not\ncall bt_subprog_enter(), which meant that backtracking continued\nmanipulating precision marks in a caller frame, while looking at\ninstructions in a callee frame.\n\nThis lead to segmentation faults during verification (see the\nselftest), or unsound state pruning.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/387b1baefbb776e3f48dc2261e77a49213f470f7","tags":[]},{"url":"https://git.kernel.org/stable/c/671b7b9a660ef15b25faa3df161205b9dc8d1eb2","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}