PT-2026-98721 · Linux · Linux

CVE-2026-98058

·

Published

2026-09-25

·

Updated

2026-09-30

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF subsystem where the bpf sys bpf() and bpf sys close() functions are not correctly marked as sleepable. The bpf sys bpf() function executes the bpf(2) syscall body, which may involve taking mutexes, allocating memory with GFP KERNEL, or waiting for an RCU grace period. Similarly, bpf sys close() can sleep during the execution of close fd() and filp close(). While these helpers are limited to BPF PROG TYPE SYSCALL, a syscall program can register a bpf timer callback. Because the prototypes lack the .might sleep attribute, the verifier may allow these functions to be invoked from an hrtimer softirq context, leading to a scheduling-while-atomic failure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98058

Affected Products

Linux