Linux Kernel BPF: Prevent dev-bound program misuse across non-offloaded netdevs
CVE-2026-98382 Published on October 9, 2026
bpf: Reject dev-bound-only programs on other devices
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject dev-bound-only programs on other devices
__bpf_offload_dev_match() falls back to comparing offdev pointers after an
exact netdev mismatch. Bound-only programs normally have NULL offdevs, so
unrelated netdevs compare equal. A bound-only program on an
offload-registered netdev can instead inherit a real offdev and match a
sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use
bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs
specialized for the bound driver on the target driver's xdp_buff. Running a
veth-bound program on tun reads beyond tun's bare stack xdp_buff as a
veth_xdp_buff.
Oops: general protection fault, probably for non-canonical address
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673)
Call Trace:
...
tun_build_skb (drivers/net/tun.c:1739)
tun_get_user (drivers/net/tun.c:1856)
tun_chr_write_iter (drivers/net/tun.c:2091)
vfs_write (fs/read_write.c:595 fs/read_write.c:687)
ksys_write (fs/read_write.c:739)
do_syscall_64 (arch/x86/entry/syscall_64.c:84)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt
Restrict non-offloaded programs to exact netdev matches and retain the
shared-offdev fallback only for genuinely offloaded multi-port programs.
Products Associated with CVE-2026-98382
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 and below e57f04194361574493e3e6cf0b9e9c69e4ae9791 is affected.
- Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 and below 0dceda331180617aeeb22381e8480b37f18ba08b is affected.
- Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 and below 940b626854de200e6187777d42114727daca617c is affected.
- Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 and below bb375f3c5990e29851894f20ebc4b9dbc6676126 is affected.
- Version 2b3486bc2d237ec345b3942b7be5deabf8c8fed1 and below 6db1ce73e9853f533eb7f413f14ba00f8ec6f80d is affected.
- Version 6.3 is affected.
- Before 6.3 is unaffected.
- Version 6.6.158, <= 6.6.* is unaffected.
- Version 6.12.112, <= 6.12.* is unaffected.
- Version 6.18.55, <= 6.18.* is unaffected.
- Version 7.2.9, <= 7.2.* is unaffected.
- Version 7.3-rc5, <= * is unaffected.