OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-98041

HIGH · CVSS 7 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's BPF (Berkeley Packet Filter) implementation, specifically in how it handles JMP32 pointer comparisons against zero. This flaw can lead to incorrect predictions in control flow, potentially allowing an attacker to manipulate program execution paths. Organizations using Linux kernel versions that include this BPF functionality should prioritize addressing this issue to mitigate potential exploitation risks.

CVE
CVE-2026-98041
Severity
HIGH
CVSS
7
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Don't predict JMP32 pointer vs zero comparisons Consider the following program: r1 = map_value; /* low 32 bits are zero at runtime */ r6 = 0xdead000000000000; if w1 != 0 goto l1; l0: r1 += r6; r2 = *(u64 *)(r1 + 0); exit; l1: r6 = 0; goto l0; At the moment is_branch_taken() reports the jump as always taken, because it does not distinguish between BPF_JMP and BPF_JMP32 comparisons when processing 'if w1 != 0 ...'.