{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "b5dc0163d8fd78e64a7e21f309cf932fda34353e"
            },
            {
              "fixed": "69a9ad004ccf5d45e534c7d503f47f643abe64b7"
            },
            {
              "fixed": "1a3a10b030c96ea88868ccc060a16827c01eaa5a"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.3.0"
            },
            {
              "fixed": "7.2.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98019.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: mark a NULL call argument precise\n\ncheck_func_arg() allows bpf_register_is_null() for nullable arguments\nw/o marking the underlying scalar register precise. Hence a checkpoint\ncreated on such a path would prune against arbitrary scalar value.\n\ncheck_helper_call() enforces second parameter of the\nbpf_get_local_storage() to be zero, w/o marking the underlying scalar\nregister precise. Hence a checkpoint created on such a path would\nprune against arbitrary scalar value.\n\nGrouping these two into one patch, as they share the same fixes tag.",
  "id": "CVE-2026-98019",
  "modified": "2026-09-27T03:30:48.468990900Z",
  "published": "2026-09-25T10:23:40.303Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1a3a10b030c96ea88868ccc060a16827c01eaa5a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/69a9ad004ccf5d45e534c7d503f47f643abe64b7"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98019.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98019"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "bpf: mark a NULL call argument precise"
}