{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "004d4b274e2a1a895a0e5dc66158b90a7d463d44"
            },
            {
              "fixed": "0f38472a2aa8704a6b514c0dfa9c32f3672b8f32"
            },
            {
              "fixed": "cae8674489f26edf7553fdd660599466cbb4c32f"
            },
            {
              "fixed": "9f9e57b5a3a033f95f49ef9d541340cdbcb80abb"
            },
            {
              "fixed": "df0072be6fc373cb22f9ea854d458b04e32a03cf"
            },
            {
              "fixed": "b9bb0e735460751b620156f800a4279a28573392"
            },
            {
              "fixed": "37b18688cd18fd86d2f35c212df1611862a26cd5"
            },
            {
              "fixed": "fca71ead7a20290af1e2046983eeafae43d21af1"
            },
            {
              "fixed": "e4a62833adff6ef0fe7c0b90393204fe3c26b5c5"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.18.0"
            },
            {
              "fixed": "5.10.271"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.222"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.189"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.55"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.9"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98383.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL\n\nAn LWT_SEG6LOCAL program can invalidate its cached SRH with\nbpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter\nmay reallocate skb-\u003ehead, leaving the per-CPU SRH pointer dangling.\nPost-program SRH validation then writes through that pointer.\n\nDisallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier\nrejects this unsafe helper combination. Other LWT program types continue\nto expose the helper through lwt_out_func_proto().",
  "id": "CVE-2026-98383",
  "modified": "2026-10-11T02:31:04.186096534Z",
  "published": "2026-10-09T07:34:22.408Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0f38472a2aa8704a6b514c0dfa9c32f3672b8f32"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/37b18688cd18fd86d2f35c212df1611862a26cd5"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9f9e57b5a3a033f95f49ef9d541340cdbcb80abb"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b9bb0e735460751b620156f800a4279a28573392"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/cae8674489f26edf7553fdd660599466cbb4c32f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/df0072be6fc373cb22f9ea854d458b04e32a03cf"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e4a62833adff6ef0fe7c0b90393204fe3c26b5c5"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/fca71ead7a20290af1e2046983eeafae43d21af1"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98383.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98383"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL"
}