PT-2026-98708 · Linux · Linux

CVE-2026-98045

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Mark faultable stack helpers as sleepable
The faultable variants of bpf get stack() and bpf get task stack() pass may fault=true into the common stack collection code. Resolving user-space build IDs may then call build id parse file() and block on filesystem reads.
Neither helper prototype sets might sleep. Since prototype selection uses the sleepability of the whole program, the verifier can still allow these helpers from a non-sleepable region within that program, such as an explicit RCU or preemption-disabled region. The task-stack helper can also be called from a non-sleepable timer callback of a sleepable program.
Mark both faultable prototypes as sleepable. The existing helper context check then rejects these calls while continuing to allow them in genuinely sleepable contexts.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98045

Affected Products

Linux