CVE-2026-98061 PUBLISHED

bpf: Reject tail calls directly from callback frames

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject tail calls directly from callback frames

A tail call from a non-zero frame is modeled as a return from that frame. The verifier makes R0 unknown and calls prepare_func_exit() for the taken branch.

When the current frame is a synchronous callback, prepare_func_exit() enforces the callback return-value contract and marks R0 precise. Since the tail-call path synthesized R0 rather than deriving it from an instruction, precision backtracking reaches the callback-calling instruction with R0 still requested and triggers the "callback unexpected regs" verifier bug. A CAP_BPF task can therefore cause a WARN and an -EFAULT BPF_PROG_LOAD.

Tail calls reachable from callbacks are already rejected later by check_max_stack_depth(). Reject a tail call made directly by a callback before constructing the inconsistent return state, using the existing diagnostic. Tail calls from ordinary subprograms keep their current behavior.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from a6c22c91b6284e4713c0cf5b20ab3c9c71b77ae8 to 617c8266e49f45747f71e74177646a63f72b7025 (excl.)
  • affected from e3245f8990431950d20631c72236d4e8cb2dcde8 to 96d31b28263c429a56e4de85bcf744a5c320b3a3 (excl.)
  • affected from e3245f8990431950d20631c72236d4e8cb2dcde8 to 266aa4ad0b2e82397cd9045752c9bff03d98eddd (excl.)
  • affected from 6.18.2 to 6.18.53 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc2 to * (incl.)

References