Linux Kernel BPF Percpu Array Map: OOB Access via Inner Map Replacement
CVE-2026-98376 Published on October 9, 2026
bpf: Use array_map_meta_equal for percpu array inner map replacement
In the Linux kernel, the following vulnerability has been resolved:
bpf: Use array_map_meta_equal for percpu array inner map replacement
percpu_array_map_ops.map_meta_equal points to the generic
bpf_map_meta_equal(), which does not compare max_entries. When a
percpu array serves as an inner map, replacing it with one that has
fewer max_entries bypasses the check. Since percpu_array_map_gen_lookup()
inlines the original template's index_mask as a JIT immediate, a lookup
on the replacement map can access pptrs[] out of bounds.
Point percpu_array_map_ops.map_meta_equal to array_map_meta_equal(),
which already enforces the max_entries equality check.
Add a selftest to verify that replacing a percpu array inner map with
a differently-sized one is rejected.
Products Associated with CVE-2026-98376
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version db69718b8efac802c7cc20d5a6c7dfc913f99c43 and below 593980175389a05793f6060aa20e626330960395 is affected.
- Version 6.10 is affected.
- Before 6.10 is unaffected.
- Version 7.1, <= * is unaffected.