{"id":"CVE-2026-98383","summary":"bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL\n\nAn LWT_SEG6LOCAL program can invalidate its cached SRH with\nbpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter\nmay reallocate skb-\u003ehead, leaving the per-CPU SRH pointer dangling.\nPost-program SRH validation then writes through that pointer.\n\nDisallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier\nrejects this unsafe helper combination. Other LWT program types continue\nto expose the helper through lwt_out_func_proto().","modified":"2026-10-11T02:46:33.042385129Z","published":"2026-10-09T07:34:22.408Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98383.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0f38472a2aa8704a6b514c0dfa9c32f3672b8f32"},{"type":"WEB","url":"https://git.kernel.org/stable/c/37b18688cd18fd86d2f35c212df1611862a26cd5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9f9e57b5a3a033f95f49ef9d541340cdbcb80abb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b9bb0e735460751b620156f800a4279a28573392"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cae8674489f26edf7553fdd660599466cbb4c32f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/df0072be6fc373cb22f9ea854d458b04e32a03cf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e4a62833adff6ef0fe7c0b90393204fe3c26b5c5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fca71ead7a20290af1e2046983eeafae43d21af1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98383.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98383"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"004d4b274e2a1a895a0e5dc66158b90a7d463d44"},{"fixed":"0f38472a2aa8704a6b514c0dfa9c32f3672b8f32"},{"fixed":"cae8674489f26edf7553fdd660599466cbb4c32f"},{"fixed":"9f9e57b5a3a033f95f49ef9d541340cdbcb80abb"},{"fixed":"df0072be6fc373cb22f9ea854d458b04e32a03cf"},{"fixed":"b9bb0e735460751b620156f800a4279a28573392"},{"fixed":"37b18688cd18fd86d2f35c212df1611862a26cd5"},{"fixed":"fca71ead7a20290af1e2046983eeafae43d21af1"},{"fixed":"e4a62833adff6ef0fe7c0b90393204fe3c26b5c5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98383.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.18.0"},{"fixed":"5.10.271"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.222"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.55"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98383.json"}}],"schema_version":"1.9.0"}