Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-98049
Linux Linux — bpf: zero extend the result of an arena 32-bit cmpxchg
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N N H 5.5 .0011 1.1 —
AFFECTED
Product Versions Fixed
Linux d503a04f8bc0c75dc9db9452d8cc79d748afb752 – —
Linux 6.10 – 7.2.7
TIMELINE
Sep 25 Reserved by Linux
Sep 25 Published (CNA: Linux)
Oct 6 ENRICHED — CVE-2026-98049 (Linux). Received CVSS 5.5 and CPE data from NVD.
Description
In the Linux kernel, the following vulnerability has been resolved:
bpf: zero extend the result of an arena 32-bit cmpxchg
bpf_convert_ctx_accesses() rewrites an atomic on an arena pointer from
BPF_STX | BPF_ATOMIC to BPF_STX | BPF_PROBE_ATOMIC, and it runs before
bpf_opt_subreg_zext_lo32_rnd_hi32().
That pass emits an explicit zero extension for a 32-bit cmpxchg even
when bpf_jit_needs_zext() is false. This is done because on some
architectures 32-bit cmpxchg requires explicit zero extension for the
dst register. E.g. on x86-64 'lock cmpxchg' does not change the %eax
if comparison is successful, while BPF semantics declare that each
operation on a 32-bit register zero extends it's upper half.
is_cmpxchg_insn() matches BPF_MODE == BPF_ATOMIC only, so an arena
cmpxchg misses said zero extension adjustment. This patch adjusts
is_cmpxchg_insn() to match BPF_PROBE_ATOMIC alongside BPF_ATOMIC.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 25, 2026 | Reserved | Reserved by Linux |
| September 25, 2026 | Published | Published (CNA: Linux) |
| October 6, 2026 | ENRICHED | ENRICHED — CVE-2026-98049 (Linux). Received CVSS 5.5 and CPE data from NVD. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | d503a04f8bc0c75dc9db9452d8cc79d748afb752 | — |
| Linux | Linux | — | 6.10 | 7.2.7 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-98049 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.