PT-2026-98700 · Linux · Linux

CVE-2026-98037

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject untrusted allocated-object pointers
When the final RCU read-side critical section ends, a local kptr is demoted to PTR UNTRUSTED but retains MEM ALLOC. The pointer may be NULL or may refer to an object whose lifetime is no longer protected.
type is ptr alloc obj() nevertheless recognizes any PTR TO BTF ID with MEM ALLOC as a live allocated object. In particular, a refcount-only local kptr never carries NON OWN REF, so it still passes the bpf refcount acquire() argument check after RCU protection ends. The kfunc can then dereference NULL or stale memory.
Make type is ptr alloc obj() reject PTR UNTRUSTED pointers. Since type is non owning ref() is based on the same predicate, graph kfunc arguments obey the same live-object requirement. Fault-protected reads of the demoted pointer remain valid: writes are already rejected, and read fixups use bpf may fault on deref() rather than this predicate.
[ kkd: Rewrote commit log ]
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98037

Produtos afetados

Linux