CVE-2026-98060 Overview
CVE-2026-98060 is a Linux kernel vulnerability in the Berkeley Packet Filter (BPF) subsystem. The flaw affects __bpf_rbtree_add(), which keeps parent and link pointers live across calls to a program-supplied comparison callback. The verifier requires the root's lock to remain held throughout the callback, but the resilient lock kfunc argument path fails to enforce this rule. A BPF program can release the root lock from within the callback, allowing another CPU to remove and free the node referenced by the in-progress tree walk. The walk then resumes using freed pointers, producing a use-after-free condition in kernel context.
Critical Impact
A local user with permission to load BPF programs can trigger a kernel use-after-free in rbtree traversal, enabling potential memory corruption and privilege escalation.
Affected Products
- Linux kernel versions implementing BPF resilient locks and rbtree kfuncs
- Distributions shipping affected mainline/stable kernels prior to the fix commits
- Systems permitting unprivileged or CAP_BPF-enabled BPF program loading
Discovery Timeline
- 2026-09-25 - CVE-2026-98060 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98060
Vulnerability Analysis
The Linux BPF subsystem supports rbtree data structures manipulated by BPF programs through helper and kfunc interfaces. When a program inserts a node via __bpf_rbtree_add(), the kernel walks the tree and invokes a program-supplied comparison callback at each level. During this traversal, the kernel holds live parent and link pointers derived from in-tree nodes.
To keep those pointers valid, the verifier mandates that the lock protecting the rbtree root remains held across the entire callback. The spin lock helper path, covering bpf_spin_lock() and bpf_spin_unlock(), correctly rejects lock state changes inside the callback. The resilient lock kfunc argument path, however, lacks the equivalent check.
Resilient locks can protect BPF rbtree roots. A malicious or buggy comparison callback can therefore invoke a resilient lock kfunc to release the root lock mid-walk. A concurrent CPU can then remove and free a node whose address is still cached by the in-progress insertion.
Root Cause
The root cause is missing policy enforcement in the resilient lock kfunc argument validation path. The verifier treats resilient lock operations as safe inside rbtree comparison callbacks, even though they violate the invariant that the root lock stays held. The fix extends the existing spin-lock rejection policy to also reject resilient lock kfuncs within rbtree comparison callbacks.
Attack Vector
Exploitation requires the ability to load a BPF program that uses rbtree kfuncs and resilient locks. An attacker crafts a comparison callback that releases the root's resilient lock, then races a second thread that removes the target node. When __bpf_rbtree_add() resumes, it dereferences freed memory, enabling kernel use-after-free primitives [CWE-416]. Technical details are available in the upstream fix commits 71930202, 7b7b8b59, and cc2e065e.
No public proof-of-concept exploit is listed for CVE-2026-98060. See the kernel commits for technical details on the fix and the affected code paths.
Detection Methods for CVE-2026-98060
Indicators of Compromise
- Unexpected kernel oops or KASAN: use-after-free reports referencing __bpf_rbtree_add or rbtree traversal functions
- Kernel panics correlated with recent bpf() syscalls from non-root processes holding CAP_BPF
- BPF programs loaded by low-privilege users that reference rbtree kfuncs together with resilient lock kfuncs
Detection Strategies
- Audit bpf() syscall activity to identify processes loading programs that combine rbtree and resilient lock kfuncs
- Enable KASAN on test and staging kernels to surface use-after-free conditions in BPF code paths
- Monitor dmesg and kernel crash telemetry for stack traces involving __bpf_rbtree_add and comparison callbacks
Monitoring Recommendations
- Collect kernel audit logs for BPF program loads and attach events across the fleet
- Alert on kernel crashes containing BPF subsystem symbols for timely incident triage
- Track running kernel versions and flag hosts still on pre-fix builds for prioritized patching
How to Mitigate CVE-2026-98060
Immediate Actions Required
- Apply vendor kernel updates that incorporate the upstream fix commits once available for your distribution
- Restrict BPF program loading to trusted administrators by removing CAP_BPF and CAP_SYS_ADMIN from non-essential accounts
- Set kernel.unprivileged_bpf_disabled=1 on systems where unprivileged BPF is not required
Patch Information
The upstream fix rejects resilient lock kfuncs inside rbtree comparison callbacks, matching the existing policy for spin lock helpers. Apply the kernel updates incorporating commits 71930202a0a0, 7b7b8b596010, and cc2e065ed206. Rebuild and reboot affected systems after patching.
Workarounds
- Disable unprivileged BPF access by setting kernel.unprivileged_bpf_disabled=1 via sysctl
- Remove CAP_BPF from user namespaces and container runtimes where BPF is not required
- Use mandatory access controls such as SELinux or AppArmor to restrict bpf() syscall usage to known workloads
# Configuration example
sysctl -w kernel.unprivileged_bpf_disabled=1
echo 'kernel.unprivileged_bpf_disabled=1' >> /etc/sysctl.d/90-bpf-hardening.conf
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.