{"success":true,"data":{"threats":[{"id":"026a115d-fe6a-4a15-900e-88b15397b839","slug":"cve-2026-98049","externalId":"CVE-2026-98049","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-98049 — In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: zero extend the result of an arena 32-bit cmpxchg\n\nbpf_convert_ctx_access…","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: zero extend the result of an arena 32-bit cmpxchg\n\nbpf_convert_ctx_accesses() rewrites an atomic on an arena pointer from\nBPF_STX | BPF_ATOMIC to BPF_STX | BPF_PROBE_ATOMIC, and it runs before\nbpf_opt_subreg_zext_lo32_rnd_hi32().\n\nThat pass emits an explicit zero extension for a 32-bit cmpxchg even\nwhen bpf_jit_needs_zext() is false. This is done because on some\narchitectures 32-bit cmpxchg requires explicit zero extension for the\ndst register. E.g. on x86-64 'lock cmpxchg' does not change the %eax\nif comparison is successful, while BPF semantics declare that each\noperation on a 32-bit register zero extends it's upper half.\n\nis_cmpxchg_insn() matches BPF_MODE == BPF_ATOMIC only, so an arena\ncmpxchg misses said zero extension adjustment. This patch adjusts\nis_cmpxchg_insn() to match BPF_PROBE_ATOMIC alongside BPF_ATOMIC.","cveId":"CVE-2026-98049","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"linux","product":"linux kernel","affectedVersions":[">= 6.10, < 7.2.7","7.3"],"cwes":["CWE-681"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://git.kernel.org/stable/c/1c1b476d43a8b6c9bc04600369dd8cc39950d98e","https://git.kernel.org/stable/c/4814ed6406f3493bd554ad046da5f7fc04833571"],"references":[{"url":"https://git.kernel.org/stable/c/1c1b476d43a8b6c9bc04600369dd8cc39950d98e","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/4814ed6406f3493bd554ad046da5f7fc04833571","type":"patch","title":"Patch"}],"epssScore":0.00107,"epssPercentile":0.01084,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-25T11:17:33.770Z","addedAt":"2026-09-25T11:50:39.490Z","updatedAt":"2026-10-06T13:50:41.209Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98049","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-98049","note":"authoritative record"}],"raw":{"id":"CVE-2026-98049","cveTags":[],"metrics":{"cvssMetricV31":[{"type":"Primary","source":"nvd@nist.gov","cvssData":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"},"impactScore":3.6,"exploitabilityScore":1.8}]},"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","product":"Linux","versions":[{"status":"affected","version":"d503a04f8bc0c75dc9db9452d8cc79d748afb752","lessThan":"1c1b476d43a8b6c9bc04600369dd8cc39950d98e","versionType":"git"},{"status":"affected","version":"d503a04f8bc0c75dc9db9452d8cc79d748afb752","lessThan":"4814ed6406f3493bd554ad046da5f7fc04833571","versionType":"git"}],"programFiles":["kernel/bpf/fixups.c"],"defaultStatus":"unaffected"},{"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","product":"Linux","versions":[{"status":"affected","version":"6.10"},{"status":"unaffected","version":"0","lessThan":"6.10","versionType":"semver"},{"status":"unaffected","version":"7.2.7","versionType":"semver","lessThanOrEqual":"7.2.*"},{"status":"unaffected","version":"7.3-rc2","versionType":"original_commit_for_fix","lessThanOrEqual":"*"}],"programFiles":["kernel/bpf/fixups.c"],"defaultStatus":"affected"}]}],"published":"2026-09-25T11:17:33.770","references":[{"url":"https://git.kernel.org/stable/c/1c1b476d43a8b6c9bc04600369dd8cc39950d98e","tags":["Patch"],"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4814ed6406f3493bd554ad046da5f7fc04833571","tags":["Patch"],"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"vulnStatus":"Analyzed","weaknesses":[{"type":"Primary","source":"nvd@nist.gov","description":[{"lang":"en","value":"CWE-681"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: zero extend the result of an arena 32-bit cmpxchg\n\nbpf_convert_ctx_accesses() rewrites an atomic on an arena pointer from\nBPF_STX | BPF_ATOMIC to BPF_STX | BPF_PROBE_ATOMIC, and it runs before\nbpf_opt_subreg_zext_lo32_rnd_hi32().\n\nThat pass emits an explicit zero extension for a 32-bit cmpxchg even\nwhen bpf_jit_needs_zext() is false. This is done because on some\narchitectures 32-bit cmpxchg requires explicit zero extension for the\ndst register. E.g. on x86-64 'lock cmpxchg' does not change the %eax\nif comparison is successful, while BPF semantics declare that each\noperation on a 32-bit register zero extends it's upper half.\n\nis_cmpxchg_insn() matches BPF_MODE == BPF_ATOMIC only, so an arena\ncmpxchg misses said zero extension adjustment. This patch adjusts\nis_cmpxchg_insn() to match BPF_PROBE_ATOMIC alongside BPF_ATOMIC."}],"lastModified":"2026-10-06T12:50:51.137","configurations":[{"nodes":[{"negate":false,"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","vulnerable":true,"matchCriteriaId":"F70EFEAC-5AFB-4B79-9877-7F142038EF90","versionEndExcluding":"7.2.7","versionStartIncluding":"6.10"},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.3:rc1:*:*:*:*:*:*","vulnerable":true,"matchCriteriaId":"11E35E1B-5DB4-4AB9-9706-CD73B799EADF"}],"operator":"OR"}]}],"sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:46:02.221Z","durationMs":6,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":"CVE-2026-98049","source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":["include"],"warnings":[]}}