0.0
NA
CVE-2026-98383
bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL An LWT_SEG6LOCAL program can invalidate its cached SRH with bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter may reallocate skb->head, leaving the per-CPU SRH pointer dangling. Post-program SRH validation then writes through that pointer. Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier rejects this unsafe helper combination. Other LWT program types continue to expose the helper through lwt_out_func_proto().

INFO

Published Date :

Oct. 9, 2026, 8:16 a.m.

Last Modified :

Oct. 9, 2026, 8:16 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-98383 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Prevent unsafe helper combination by disallowing bpf_skb_pull_data() for LWT_SEG6LOCAL programs.
  • Update the Linux kernel to the latest version.
  • Ensure verifier rejects unsafe helper combinations.
  • Apply relevant security patches promptly.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-98383 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-98383 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-98383 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-98383 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Oct. 09, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL An LWT_SEG6LOCAL program can invalidate its cached SRH with bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter may reallocate skb->head, leaving the per-CPU SRH pointer dangling. Post-program SRH validation then writes through that pointer. Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier rejects this unsafe helper combination. Other LWT program types continue to expose the helper through lwt_out_func_proto().
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/98xxx/CVE-2026-98383.json">CVE-2026-98383</a>
    Added Reference https://git.kernel.org/stable/c/0f38472a2aa8704a6b514c0dfa9c32f3672b8f32
    Added Reference https://git.kernel.org/stable/c/37b18688cd18fd86d2f35c212df1611862a26cd5
    Added Reference https://git.kernel.org/stable/c/9f9e57b5a3a033f95f49ef9d541340cdbcb80abb
    Added Reference https://git.kernel.org/stable/c/b9bb0e735460751b620156f800a4279a28573392
    Added Reference https://git.kernel.org/stable/c/cae8674489f26edf7553fdd660599466cbb4c32f
    Added Reference https://git.kernel.org/stable/c/df0072be6fc373cb22f9ea854d458b04e32a03cf
    Added Reference https://git.kernel.org/stable/c/e4a62833adff6ef0fe7c0b90393204fe3c26b5c5
    Added Reference https://git.kernel.org/stable/c/fca71ead7a20290af1e2046983eeafae43d21af1
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.