---
id: CVE-2026-98376
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Use array_map_meta_equal for percpu array inner map replacement

  percpu_array_map_ops.map_meta_equal points to the generic
  bpf_map_meta_equal(), which does not com…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Use array_map_meta_equal for percpu array inner map replacement

  percpu_array_map_ops.map_meta_equal points to the generic
  bpf_map_meta_equal(), which does not com…
severity: none
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T08:16:55.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98376'
references:
  - url: 'https://git.kernel.org/stable/c/593980175389a05793f6060aa20e626330960395'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
ingestedAt: '2026-10-09T08:29:41.346Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: Use array_map_meta_equal for percpu array inner map replacement

percpu_array_map_ops.map_meta_equal points to the generic
bpf_map_meta_equal(), which does not compare max_entries.  When a
percpu array serves as an inner map, replacing it with one that has
fewer max_entries bypasses the check.  Since percpu_array_map_gen_lookup()
inlines the original template's index_mask as a JIT immediate, a lookup
on the replacement map can access pptrs[] out of bounds.

Point percpu_array_map_ops.map_meta_equal to array_map_meta_equal(),
which already enforces the max_entries equality check.

Add a selftest to verify that replacing a percpu array inner map with
a differently-sized one is rejected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
