---
id: CVE-2026-98075
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: reject BPF_PSEUDO_FUNC reference to the main program

  fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real
  function addresses
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: reject BPF_PSEUDO_FUNC reference to the main program

  fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real
  function addresses. This function is i…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 69c087ba6225b574afb6e505b72cb75242a3d844 <
    118212417ba0120d99f84154799f8880f07411f4
  - >-
    Linux >= 69c087ba6225b574afb6e505b72cb75242a3d844 <
    d6c39774ae093c9f7009cc4ae918f18fc1af7ae7
  - >-
    Linux >= 69c087ba6225b574afb6e505b72cb75242a3d844 <
    92f0bd0e2b632c6565ac2214a4d7d2ed37e5b9f6
  - >-
    Linux >= 69c087ba6225b574afb6e505b72cb75242a3d844 <
    374b2c5561db80fcdd7cdce44af37a49416f61c7
  - Linux 5.13
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:36.847'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98075'
references:
  - url: 'https://git.kernel.org/stable/c/118212417ba0120d99f84154799f8880f07411f4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/374b2c5561db80fcdd7cdce44af37a49416f61c7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/92f0bd0e2b632c6565ac2214a4d7d2ed37e5b9f6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d6c39774ae093c9f7009cc4ae918f18fc1af7ae7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.838Z'
epss: 0.00168
epssPercentile: 0.05414
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: reject BPF_PSEUDO_FUNC reference to the main program

fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real
function addresses. This function is invoked from bpf_jit_subprogs()
only when env->subprog_cnt > 1. Meaning that for any program like
below:

  int main(void *ctx) {
    void *ptr = main;
    ...
    bpf_timer_set_callback(..., ptr);
    ...
  }

The 'ptr' won't be ever converted to contain an address.
In combination with e.g. bpf_timer_set_callback() this would lead to a
function call at a bogus address.

Instead of complicating the implementation, just assume that no useful
program needs main to be a sync or async callback and reject
BPF_PSEUDO_FUNC loads for the main subprogram.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
