PT-2026-98726 · Linux · Linux

CVE-2026-98063

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix NULL-ptr-deref in btf var show()
btf var show() calls btf type id resolve() unconditionally, which dereferences btf->resolved ids. That is NULL for a base BTF - e.g. the vmlinux BTF that bpf snprintf btf() renders against - since base BTF is not resolved during parsing. btf modifier show() guards this with 'if (btf->resolved ids)', but btf var show() does not.
A BPF program that passes the type id of a BTF KIND VAR from the vmlinux BTF to bpf snprintf btf() thus NULL-derefs:
KASAN: probably user-memory-access in range [0x46638-0x4663f] RIP: 0010:btf var show (kernel/bpf/btf.c:2929) Call Trace: btf type show (kernel/bpf/btf.c:8259) btf type snprintf show (kernel/bpf/btf.c:8329) bpf snprintf btf (kernel/trace/bpf trace.c:1047) bpf prog test run raw tp (net/bpf/test run.c:829) sys bpf (kernel/bpf/syscall.c:4804) do syscall 64 (arch/x86/entry/syscall 64.c:84) entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121)
Resolve the var's type directly with btf type skip modifiers() when resolved ids is NULL, mirroring btf modifier show().
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98063

Produtos afetados

Linux