CVE-2026-98060 PUBLISHED

bpf: Reject resilient lock operations in rbtree callbacks

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject resilient lock operations in rbtree callbacks

__bpf_rbtree_add() keeps parent and link pointers live across calls to the program-supplied comparison callback. The verifier therefore requires the root's lock to remain held throughout the callback.

The helper path enforces this rule for bpf_spin_lock() and bpf_spin_unlock(), but the resilient lock kfunc argument path does not. Since resilient locks may protect BPF rbtree roots, a callback can release the root lock and let another CPU remove and free the node referenced by the in-progress tree walk. The walk then resumes using freed pointers.

Reject resilient lock kfuncs in an rbtree comparison callback, matching the existing policy for the spin lock helpers. Resilient-lock-protected trees remain valid when their comparison callbacks leave lock state alone.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 0de2046137f976e7302d43ac01d9894d07ac1fff to cc2e065ed206aecd9b94564779244f3ffb26e356 (excl.)
  • affected from 0de2046137f976e7302d43ac01d9894d07ac1fff to 71930202a0a0c49f0a3b45b41907a074cb780266 (excl.)
  • affected from 0de2046137f976e7302d43ac01d9894d07ac1fff to 7b7b8b5960102566bd625ae829d1f330c5b5d104 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.15 is affected
  • unaffected from 0 to 6.15 (excl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc2 to * (incl.)

References