PT-2026-98722 · Linux · Linux
CVE-2026-98059
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Mark sched process wait argument as nullable
do wait() passes wo->wo pid to the sched process wait tracepoint.
kernel wait4() leaves wo pid NULL for wait4(-1), and
kernel waitid prepare() does likewise for waitid(P ALL).
btf ctx access() currently types argument 0 as PTR TO BTF ID |
PTR TRUSTED. Without PTR MAYBE NULL, the verifier accepts an unchecked
dereference. Trusted pointer loads have no fault protection, so a wait for
any child can then cause a NULL pointer dereference in JITed BPF code.
Add sched process wait to raw tp null args[] with argument 0 marked
nullable. The verifier rejects an unchecked dereference while preserving
access after the program checks the pointer for NULL.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux