{"id":"CVE-2026-98033","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve inner map identity in callback frames\n\nCallback frame constructors initialize map-typed argument registers with\n__mark_reg_known_zero() and then restore m…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve inner map identity in callback frames\n\nCallback frame constructors initialize map-typed argument registers with\n__mark_reg_known_zero() and then restore m…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 69c087ba6225b574afb6e505b72cb75242a3d844 < 66ff2eff093d2a0838f39c713eeb590bc0946c2a","Linux >= 69c087ba6225b574afb6e505b72cb75242a3d844 < b90c5d770dad910fb89e6c1b15052a8a1e8db752","Linux 5.13"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T11:17:32.003","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98033","references":[{"url":"https://git.kernel.org/stable/c/66ff2eff093d2a0838f39c713eeb590bc0946c2a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b90c5d770dad910fb89e6c1b15052a8a1e8db752","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.851Z","slug":"CVE-2026-98033","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve inner map identity in callback frames\n\nCallback frame constructors initialize map-typed argument registers with\n__mark_reg_known_zero() and then restore map_ptr. This clears map_uid,\nwhich is the only field distinguishing inner maps that share an\ninner_map_meta template.\n\nWhen a timer callback invokes bpf_for_each_map_elem() on a second inner\nmap, both the saved first map and the second map value can reach the nested\ncallback as the same template with map_uid zero. bpf_timer_init() then\naccepts pairing the timer from the second map with the first map.\n\nThe runtime records the first map in the timer without taking a reference.\nFreeing that map does not find the timer stored in the second map, so a\nlater timer callback dereferences the freed map.\n\nCopy map_uid from the same caller register as map_ptr when constructing\nfor-each, timer/workqueue, and task-work callback arguments. The existing\nidentity check can then reject mismatched inner maps while allowing a\ncallback value to be paired with its actual map.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}