PT-2026-98700 · Linux · Linux

CVE-2026-98037

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject untrusted allocated-object pointers
When the final RCU read-side critical section ends, a local kptr is demoted to PTR UNTRUSTED but retains MEM ALLOC. The pointer may be NULL or may refer to an object whose lifetime is no longer protected.
type is ptr alloc obj() nevertheless recognizes any PTR TO BTF ID with MEM ALLOC as a live allocated object. In particular, a refcount-only local kptr never carries NON OWN REF, so it still passes the bpf refcount acquire() argument check after RCU protection ends. The kfunc can then dereference NULL or stale memory.
Make type is ptr alloc obj() reject PTR UNTRUSTED pointers. Since type is non owning ref() is based on the same predicate, graph kfunc arguments obey the same live-object requirement. Fault-protected reads of the demoted pointer remain valid: writes are already rejected, and read fixups use bpf may fault on deref() rather than this predicate.
[ kkd: Rewrote commit log ]
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98037

Affected Products

Linux