CVE-2026-98007 PUBLISHED

bpf: Reject non-scalar bpf_loop iteration counts

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject non-scalar bpf_loop iteration counts

bpf_loop() declares its nr_loops argument as ARG_ANYTHING. Privileged programs may pass pointer values to such arguments, so check_func_arg() lets a pointer-valued R1 reach the helper-specific checks.

Since commit bb124da69c47 ("bpf: keep track of max number of bpf_loop callback iterations"), the verifier marks R1 precise and reads its upper bound to limit callback simulation. Precision backtracking only accepts scalar registers, so passing a pointer instead triggers the "backtracking misuse" verifier warning. Kernels with panic_on_warn enabled subsequently panic.

Introduce ARG_SCALAR for helper arguments that only accept scalar values and use it for bpf_loop() nr_loops. Generic helper argument validation then rejects pointers before loop inlining and precision processing.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from bb124da69c47dd98d69361ec13244ece50bec63e to 656d40d1ca228ee21a9b3280432479fc9eae75ab (excl.)
  • affected from bb124da69c47dd98d69361ec13244ece50bec63e to e2e1161e03fecff6d2229a81b024337144bfcd97 (excl.)
  • affected from bb124da69c47dd98d69361ec13244ece50bec63e to f8ae8275c721334ee50fafdd986fb83294eb941a (excl.)
  • affected from bb124da69c47dd98d69361ec13244ece50bec63e to c3fd8e5fd100f122bad503bdc0e9277219533253 (excl.)
  • Version bfc5c19b4b48840627af0d0f1c8f4461b276e508 is affected
  • affected from 6.6.15 to 6.7 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.7 is affected
  • unaffected from 0 to 6.7 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc2 to * (incl.)

References