boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-98049

Linux Linux — bpf: zero extend the result of an arena 32-bit cmpxchg
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  N  N  H    5.5   .0011    1.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    d503a04f8bc0c75dc9db9452d8cc79d748afb752 –  —
  Linux    6.10 –                                      7.2.7
TIMELINE
  Sep 25  Reserved by Linux
  Sep 25  Published (CNA: Linux)
  Oct 6   ENRICHED — CVE-2026-98049 (Linux). Received CVSS 5.5 and CPE data from NVD.
CWE-681 · CNA: Linux · CVSS v3.1 · 2 references · NVD status: Analyzed

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: zero extend the result of an arena 32-bit cmpxchg bpf_convert_ctx_accesses() rewrites an atomic on an arena pointer from BPF_STX | BPF_ATOMIC to BPF_STX | BPF_PROBE_ATOMIC, and it runs before bpf_opt_subreg_zext_lo32_rnd_hi32(). That pass emits an explicit zero extension for a 32-bit cmpxchg even when bpf_jit_needs_zext() is false. This is done because on some architectures 32-bit cmpxchg requires explicit zero extension for the dst register. E.g. on x86-64 'lock cmpxchg' does not change the %eax if comparison is successful, while BPF semantics declare that each operation on a 32-bit register zero extends it's upper half. is_cmpxchg_insn() matches BPF_MODE == BPF_ATOMIC only, so an arena cmpxchg misses said zero extension adjustment. This patch adjusts is_cmpxchg_insn() to match BPF_PROBE_ATOMIC alongside BPF_ATOMIC.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 25, 2026ReservedReserved by Linux
September 25, 2026PublishedPublished (CNA: Linux)
October 6, 2026ENRICHEDENRICHED — CVE-2026-98049 (Linux). Received CVSS 5.5 and CPE data from NVD.

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinux—d503a04f8bc0c75dc9db9452d8cc79d748afb752—
LinuxLinux—6.107.2.7

Weaknesses

CWE-681

References (2)

Related

Authoritative record: CVE-2026-98049 at cve.org

Vendors: linux

Weaknesses: CWE-681

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-98049 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.