{"api_version":"1","generated_at":"2026-10-05T11:10:26+00:00","cve":"CVE-2026-98036","urls":{"html":"https://cve.report/CVE-2026-98036","api":"https://cve.report/api/cve/CVE-2026-98036.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-98036","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-98036"},"summary":{"title":"bpf: Preserve special fields in recycled rhtab elements","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve special fields in recycled rhtab elements\n\nrhtab_map_update_elem() initializes special fields after obtaining an\nelement from bpf_mem_cache_alloc(). The allocator can return a fresh,\nzeroed unit, or recycle one from its RCU-pending lists before the\nregistered destructor has run.\n\nA BPF program can retain a map-value pointer after deleting its element\nand initialize and arm a timer through that pointer. If the deleted unit\nis recycled, check_and_init_map_value() clears the only pointer to the\ntimer. Neither a later deletion nor rhtab_mem_dtor() can then cancel it,\nand the callback can run with its key and value pointing into freed memory.\n\nDo not reinitialize special fields on insertion. Fresh allocator units are\nalready zeroed. For recycled units, the special fields are ownership state\nthat must remain visible to the eventual destructor. copy_map_value()\nalready skips those fields, matching the non-preallocated hash-map path and\nthe lifecycle established by commit 275c30bcee66 (\"bpf: Don't reinit map\nvalue in prealloc_lru_pop\").\n\n[ kkd: Split out the fix and rewrote the commit log ]","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:32","updated_at":"2026-09-25 11:17:32"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/6a5266b8288216b86602ff687d528abfb066dfd8","name":"https://git.kernel.org/stable/c/6a5266b8288216b86602ff687d528abfb066dfd8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5df46ddcb7b36878c1b691e9057a0509042a2567","name":"https://git.kernel.org/stable/c/5df46ddcb7b36878c1b691e9057a0509042a2567","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98036","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98036","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6905f8601298ecd2d1932a4b4849bf265201118e 6a5266b8288216b86602ff687d528abfb066dfd8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6905f8601298ecd2d1932a4b4849bf265201118e 5df46ddcb7b36878c1b691e9057a0509042a2567 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"98036","cve":"CVE-2026-98036","epss":"0.001550000","percentile":"0.039780000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/bpf/hashtab.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6a5266b8288216b86602ff687d528abfb066dfd8","status":"affected","version":"6905f8601298ecd2d1932a4b4849bf265201118e","versionType":"git"},{"lessThan":"5df46ddcb7b36878c1b691e9057a0509042a2567","status":"affected","version":"6905f8601298ecd2d1932a4b4849bf265201118e","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["kernel/bpf/hashtab.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.2"},{"lessThan":"7.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"7.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc2","versionStartIncluding":"7.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve special fields in recycled rhtab elements\n\nrhtab_map_update_elem() initializes special fields after obtaining an\nelement from bpf_mem_cache_alloc(). The allocator can return a fresh,\nzeroed unit, or recycle one from its RCU-pending lists before the\nregistered destructor has run.\n\nA BPF program can retain a map-value pointer after deleting its element\nand initialize and arm a timer through that pointer. If the deleted unit\nis recycled, check_and_init_map_value() clears the only pointer to the\ntimer. Neither a later deletion nor rhtab_mem_dtor() can then cancel it,\nand the callback can run with its key and value pointing into freed memory.\n\nDo not reinitialize special fields on insertion. Fresh allocator units are\nalready zeroed. For recycled units, the special fields are ownership state\nthat must remain visible to the eventual destructor. copy_map_value()\nalready skips those fields, matching the non-preallocated hash-map path and\nthe lifecycle established by commit 275c30bcee66 (\"bpf: Don't reinit map\nvalue in prealloc_lru_pop\").\n\n[ kkd: Split out the fix and rewrote the commit log ]"}],"providerMetadata":{"dateUpdated":"2026-09-25T10:23:50.530Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/6a5266b8288216b86602ff687d528abfb066dfd8"},{"url":"https://git.kernel.org/stable/c/5df46ddcb7b36878c1b691e9057a0509042a2567"}],"title":"bpf: Preserve special fields in recycled rhtab elements","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-98036","datePublished":"2026-09-25T10:23:50.530Z","dateReserved":"2026-09-25T10:19:56.071Z","dateUpdated":"2026-09-25T10:23:50.530Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:32","lastModifiedDate":"2026-09-25 11:17:32","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"98036","Ordinal":"1","Title":"bpf: Preserve special fields in recycled rhtab elements","CVE":"CVE-2026-98036","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"98036","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve special fields in recycled rhtab elements\n\nrhtab_map_update_elem() initializes special fields after obtaining an\nelement from bpf_mem_cache_alloc(). The allocator can return a fresh,\nzeroed unit, or recycle one from its RCU-pending lists before the\nregistered destructor has run.\n\nA BPF program can retain a map-value pointer after deleting its element\nand initialize and arm a timer through that pointer. If the deleted unit\nis recycled, check_and_init_map_value() clears the only pointer to the\ntimer. Neither a later deletion nor rhtab_mem_dtor() can then cancel it,\nand the callback can run with its key and value pointing into freed memory.\n\nDo not reinitialize special fields on insertion. Fresh allocator units are\nalready zeroed. For recycled units, the special fields are ownership state\nthat must remain visible to the eventual destructor. copy_map_value()\nalready skips those fields, matching the non-preallocated hash-map path and\nthe lifecycle established by commit 275c30bcee66 (\"bpf: Don't reinit map\nvalue in prealloc_lru_pop\").\n\n[ kkd: Split out the fix and rewrote the commit log ]","Type":"Description","Title":"bpf: Preserve special fields in recycled rhtab elements"}]}}}