PT-2026-98726 · Linux · Linux
CVE-2026-98063
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix NULL-ptr-deref in btf var show()
btf var show() calls btf type id resolve() unconditionally, which
dereferences btf->resolved ids. That is NULL for a base BTF - e.g. the
vmlinux BTF that bpf snprintf btf() renders against - since base BTF is
not resolved during parsing. btf modifier show() guards this with
'if (btf->resolved ids)', but btf var show() does not.
A BPF program that passes the type id of a BTF KIND VAR from the vmlinux
BTF to bpf snprintf btf() thus NULL-derefs:
KASAN: probably user-memory-access in range [0x46638-0x4663f]
RIP: 0010:btf var show (kernel/bpf/btf.c:2929)
Call Trace:
btf type show (kernel/bpf/btf.c:8259)
btf type snprintf show (kernel/bpf/btf.c:8329)
bpf snprintf btf (kernel/trace/bpf trace.c:1047)
bpf prog test run raw tp (net/bpf/test run.c:829)
sys bpf (kernel/bpf/syscall.c:4804)
do syscall 64 (arch/x86/entry/syscall 64.c:84)
entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121)
Resolve the var's type directly with btf type skip modifiers() when
resolved ids is NULL, mirroring btf modifier show().
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux