PT-2026-98726 · Linux · Linux

CVE-2026-98063

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix NULL-ptr-deref in btf var show()
btf var show() calls btf type id resolve() unconditionally, which dereferences btf->resolved ids. That is NULL for a base BTF - e.g. the vmlinux BTF that bpf snprintf btf() renders against - since base BTF is not resolved during parsing. btf modifier show() guards this with 'if (btf->resolved ids)', but btf var show() does not.
A BPF program that passes the type id of a BTF KIND VAR from the vmlinux BTF to bpf snprintf btf() thus NULL-derefs:
KASAN: probably user-memory-access in range [0x46638-0x4663f] RIP: 0010:btf var show (kernel/bpf/btf.c:2929) Call Trace: btf type show (kernel/bpf/btf.c:8259) btf type snprintf show (kernel/bpf/btf.c:8329) bpf snprintf btf (kernel/trace/bpf trace.c:1047) bpf prog test run raw tp (net/bpf/test run.c:829) sys bpf (kernel/bpf/syscall.c:4804) do syscall 64 (arch/x86/entry/syscall 64.c:84) entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121)
Resolve the var's type directly with btf type skip modifiers() when resolved ids is NULL, mirroring btf modifier show().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98063

Affected Products

Linux