{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  bpf: Don't infer non-NULL from a pointer with an unbounded offset  reg_not_null() decides that a register holds a non-NULL value by looking at its type alone. For pointer types that allow arithmetic the type only guarantees a non-NULL base, in case of an unbound offset the runtime offset value might still add up to NULL. Consider the followng program:    r6 = bpf_map_lookup_elem(map, \u00260);  /* present */   if (r6 == 0) return 0;   r7 = bpf_map_lookup_elem(map, \u00261);  /* absent, NULL at runtime */   r8 = r7;   r8 -= r6;     /* pointer - pointer: unknown scalar, -r6 */   r8 \u003c\u003c= 1;   r8 \u003e\u003e= 1;     /* any non-negative offset is accepted by */                 /* check_reg_sane_offset_ptr() */   r6 += r8;     /* verifier: map value;    runtime: zero  */   if (r7 != r6) return 0;   *(u8 *)(r7 + 0);  /* r7 is inferred non-NULL, both are zero */  At runtime both registers are zero, the comparison is true and the load faults with NULL pointer dereference.  Require the offset to be within +-BPF_MAX_VAR_OFF in reg_not_null().",
  "id": "DEBIAN-CVE-2026-98043",
  "modified": "2026-09-26T04:47:32.222663643Z",
  "published": "2026-09-25T11:17:33.090Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98043"
    }
  ],
  "upstream": [
    "CVE-2026-98043"
  ]
}