PT-2026-98709 · Linux · Linux
CVE-2026-98046
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Mark bpf btf find by name kind() as sleepable
When bpf btf find by name kind() finds a type in module BTF, it
returns a new BTF object fd through btf new fd(). This reaches
anon inode getfd(), which can sleep while allocating or expanding the
current task fd table.
The helper prototype does not set might sleep, so the verifier allows
the helper in non-sleepable contexts such as BPF timer callbacks. The
fd allocation can then sleep in softirq context and install the fd into
the interrupted task.
Mark the helper as sleepable. This preserves calls from the main body
of a sleepable syscall program while rejecting calls from its
non-sleepable regions.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux