PT-2026-98700 · Linux · Linux
CVE-2026-98037
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject untrusted allocated-object pointers
When the final RCU read-side critical section ends, a local kptr is demoted
to PTR UNTRUSTED but retains MEM ALLOC. The pointer may be NULL or may refer
to an object whose lifetime is no longer protected.
type is ptr alloc obj() nevertheless recognizes any PTR TO BTF ID with
MEM ALLOC as a live allocated object. In particular, a refcount-only local
kptr never carries NON OWN REF, so it still passes the
bpf refcount acquire() argument check after RCU protection ends. The kfunc
can then dereference NULL or stale memory.
Make type is ptr alloc obj() reject PTR UNTRUSTED pointers. Since
type is non owning ref() is based on the same predicate, graph kfunc
arguments obey the same live-object requirement. Fault-protected reads of
the demoted pointer remain valid: writes are already rejected, and read
fixups use bpf may fault on deref() rather than this predicate.
[ kkd: Rewrote commit log ]
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux