{"id":"AZL-104372","summary":"CVE-2026-98075 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: reject BPF_PSEUDO_FUNC reference to the main program\n\nfixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real\nfunction addresses. This function is invoked from bpf_jit_subprogs()\nonly when env-\u003esubprog_cnt \u003e 1. Meaning that for any program like\nbelow:\n\n  int main(void *ctx) {\n    void *ptr = main;\n    ...\n    bpf_timer_set_callback(..., ptr);\n    ...\n  }\n\nThe 'ptr' won't be ever converted to contain an address.\nIn combination with e.g. bpf_timer_set_callback() this would lead to a\nfunction call at a bogus address.\n\nInstead of complicating the implementation, just assume that no useful\nprogram needs main to be a sync or async callback and reject\nBPF_PSEUDO_FUNC loads for the main subprogram.","modified":"2026-09-28T05:39:54Z","published":"2026-09-25T11:17:36Z","upstream":["CVE-2026-98075"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98075"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104372.json"}}],"schema_version":"1.9.0"}