CVE-2026-98378 Linux 内核 BPF 链接迭代器释放后使用漏洞
影响本地攻击者可触发释放后使用,导致内核内存破坏或系统崩溃
Linux 内核 BPF 子系统中,bpf_link_prime() 会在 anon_inode_getfile() 成功前将链接插入 link_idr,此时链接的 ID 尚未发布(ID 为零)。bpf_link_by_id() 会将此类 ID 为零的链接视为未就绪,但链接迭代器在取引用时缺少同样的检查。若 anon_inode_getfile() 随后失败,创建者会移除该 ID 并直接释放仍属私有的链接,迭代器便持有悬空引用,其后续 bpf_link_put() 会访问已释放内存。
影响范围
受影响范围为存在该缺陷的 Linux 内核 BPF 链接迭代器实现;具体受影响版本范围暂无公开信息。
漏洞详情
该漏洞属于释放后使用(use-after-free)类型,成因是链接迭代器未像 bpf_link_by_id() 那样跳过 ID 为零的未就绪链接。当 anon_inode_getfile() 失败时,链接被创建者直接释放,而迭代器仍持有其引用,随后调用 bpf_link_put() 即访问已释放内存。KASAN 报告显示在 bpf_link_put 中出现 slab-use-after-free,调用链经由 bpf_link_seq_next 与 bpf_seq_read。
利用条件与风险
利用前提是攻击者能在本地触发 BPF 链接迭代并制造 anon_inode_getfile() 失败路径,通常需要本地低权限访问。实战中可导致内核内存破坏、系统崩溃或潜在权限提升,但利用难度较高。
修复建议
官方修复方案是在 bpf_link_get_curr_or_next() 中将 ID 为零的条目视为瞬态并跳过,与 bpf_link_by_id() 保持一致。临时缓解措施暂无公开信息,建议及时更新内核至包含该修复的版本。
In the Linux kernel, the following vulnerability has been resolved:
bpf: Skip unsettled links in link iterator
bpf_link_prime() inserts a link into link_idr before anon_inode_getfile()
succeeds and before bpf_link_settle() publishes the ID in link->id.
bpf_link_by_id() treats such an ID-zero link as unsettled, but the link
iterator takes a reference without this check.
If anon_inode_getfile() then fails, the creator removes the ID and frees
its still-private link directly. The iterator is left with a dangling
reference and its next bpf_link_put() accesses freed memory.
Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as
bpf_link_by_id() does.
BUG: KASAN: slab-use-after-free in bpf_link_put
Write of size 8 by task exp/384
Call Trace:
bpf_link_put kernel/bpf/syscall.c:3372
bpf_link_seq_next kernel/bpf/link_iter.c:33
bpf_seq_read kernel/bpf/bpf_iter.c:158
vfs_read fs/read_write.c:572
ksys_read fs/read_write.c:716
do_syscall_64 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121
Kernel panic – not syncing: KASAN: panic_on_warn set …