PT-2026-98709 · Linux · Linux

CVE-2026-98046

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Mark bpf btf find by name kind() as sleepable
When bpf btf find by name kind() finds a type in module BTF, it returns a new BTF object fd through btf new fd(). This reaches anon inode getfd(), which can sleep while allocating or expanding the current task fd table.
The helper prototype does not set might sleep, so the verifier allows the helper in non-sleepable contexts such as BPF timer callbacks. The fd allocation can then sleep in softirq context and install the fd into the interrupted task.
Mark the helper as sleepable. This preserves calls from the main body of a sleepable syscall program while rejecting calls from its non-sleepable regions.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98046

Affected Products

Linux