CVE-2026-98061 Overview
CVE-2026-98061 is a Linux kernel vulnerability in the Berkeley Packet Filter (BPF) verifier. The flaw allows a task with the CAP_BPF capability to trigger a verifier WARN and an -EFAULT failure during BPF_PROG_LOAD. The issue stems from how the verifier models tail calls originating directly from synchronous callback frames, leading to inconsistent register state during precision backtracking.
Critical Impact
A local user with CAP_BPF can load a crafted BPF program that triggers a kernel verifier bug, producing a kernel warning and causing the program load to fail with -EFAULT.
Affected Products
- Linux kernel (upstream) versions containing the BPF verifier tail-call handling for callback frames
- Stable kernel branches referenced by the fix commits 266aa4a, 617c826, and 96d31b2
- Distribution kernels derived from the affected upstream trees
Discovery Timeline
- 2026-09-25 - CVE-2026-98061 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98061
Vulnerability Analysis
The Linux BPF verifier models a tail call from a non-zero frame as a return from that frame. The verifier marks register R0 as unknown and invokes prepare_func_exit() for the taken branch. When the current frame is a synchronous callback, prepare_func_exit() enforces the callback return-value contract and marks R0 precise.
Because the tail-call path synthesizes R0 rather than deriving it from a real instruction, precision backtracking propagates the request for R0 back to the callback-calling instruction. The verifier reaches an inconsistent state and triggers the "callback unexpected regs" verifier bug. The result is a kernel WARN and an -EFAULT return from BPF_PROG_LOAD.
Root Cause
The root cause is a logic flaw in the verifier's state construction. Tail calls that are reachable through callbacks are already rejected later by check_max_stack_depth(), but the verifier builds an inconsistent return state before that check runs. The fix rejects a tail call made directly by a callback earlier, before the inconsistent state is constructed, reusing the existing diagnostic path. Tail calls from ordinary subprograms retain their current behavior.
Attack Vector
Exploitation requires local access and the CAP_BPF capability. An attacker loads a crafted eBPF program that performs a tail call directly from inside a synchronous callback frame. On an unpatched kernel, the verifier triggers a WARN_ON splat in the kernel log and returns -EFAULT from BPF_PROG_LOAD. The condition is a verifier correctness bug rather than a memory-safety primitive, but it produces repeatable kernel warnings that can be used to pollute logs or probe kernel internals.
Technical details are available in the upstream commits: Kernel Git Commit 266aa4a, Kernel Git Commit 617c826, and Kernel Git Commit 96d31b2.
Detection Methods for CVE-2026-98061
Indicators of Compromise
- Kernel log entries containing the verifier string callback unexpected regs or a related WARN_ON splat originating from the BPF verifier
- BPF_PROG_LOAD syscalls returning -EFAULT from processes that are not expected to load BPF programs
- Unexpected processes holding or using the CAP_BPF capability outside of known workloads
Detection Strategies
- Monitor dmesg and /var/log/kern.log for new BPF verifier warnings, especially stack traces referencing prepare_func_exit or callback-related verifier paths
- Audit bpf() syscall activity using auditd rules on syscall number 321 to correlate failing loads with the issuing process
- Compare running kernel versions against the fixed stable branches identified in the upstream commits
Monitoring Recommendations
- Forward kernel ring buffer events to a centralized log pipeline to catch verifier warnings in real time
- Alert on repeated BPF_PROG_LOAD failures from the same UID or process, which may indicate exploitation attempts
- Track grants and uses of CAP_BPF across the fleet and treat unexpected holders as a priority investigation
How to Mitigate CVE-2026-98061
Immediate Actions Required
- Apply the upstream fix contained in commits 266aa4a, 617c826, and 96d31b2 or update to a distribution kernel that incorporates them
- Inventory hosts that permit unprivileged BPF or that grant CAP_BPF to non-root service accounts, and reduce that attack surface where possible
- Restart affected systems after patching so the fixed kernel is active
Patch Information
The fix rejects a tail call made directly by a callback before the verifier constructs the inconsistent return state, using the existing diagnostic. The upstream patches are available at Kernel Git Commit 266aa4a, Kernel Git Commit 617c826, and Kernel Git Commit 96d31b2. Consult your Linux distribution's security tracker for backported package versions.
Workarounds
- Set kernel.unprivileged_bpf_disabled=1 via sysctl to prevent BPF program loading by unprivileged users
- Remove or restrict the CAP_BPF capability on service accounts, container runtimes, and workloads that do not require it
- Use seccomp or Linux Security Modules such as SELinux or AppArmor to block the bpf() syscall for untrusted processes
# Disable unprivileged BPF program loading
sysctl -w kernel.unprivileged_bpf_disabled=1
echo "kernel.unprivileged_bpf_disabled=1" >> /etc/sysctl.d/90-bpf-hardening.conf
# Verify the running kernel version against patched builds
uname -r
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.