PT-2026-98700 · Linux · Linux
CVE-2026-98037
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject untrusted allocated-object pointers
When the final RCU read-side critical section ends, a local kptr is demoted
to PTR UNTRUSTED but retains MEM ALLOC. The pointer may be NULL or may refer
to an object whose lifetime is no longer protected.
type is ptr alloc obj() nevertheless recognizes any PTR TO BTF ID with
MEM ALLOC as a live allocated object. In particular, a refcount-only local
kptr never carries NON OWN REF, so it still passes the
bpf refcount acquire() argument check after RCU protection ends. The kfunc
can then dereference NULL or stale memory.
Make type is ptr alloc obj() reject PTR UNTRUSTED pointers. Since
type is non owning ref() is based on the same predicate, graph kfunc
arguments obey the same live-object requirement. Fault-protected reads of
the demoted pointer remain valid: writes are already rejected, and read
fixups use bpf may fault on deref() rather than this predicate.
[ kkd: Rewrote commit log ]
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux