PT-2026-98727 · Linux · Linux
CVE-2026-98064
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix NULL-ptr-deref when showing a void BTF type
btf modifier show() resolves the modifier and then calls
btf type ops(t)->show() unconditionally. For the void type (type id 0,
BTF KIND UNKN) kind ops[] has no entry, so ->show is NULL.
A "const void" (a modifier resolving to void) cannot be a map key or
value - map check btf() rejects it because void has no size - so the map
dump path does not reach it. But bpf snprintf btf() takes a type id
straight from the BPF program, and passing such a "const void" from the
vmlinux BTF NULL-derefs:
KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]
RIP: 0010:btf modifier show (kernel/bpf/btf.c:2914)
Call Trace:
btf type show (kernel/bpf/btf.c:8251)
btf type snprintf show (kernel/bpf/btf.c:8321)
bpf snprintf btf (kernel/trace/bpf trace.c:1047)
bpf prog test run raw tp (net/bpf/test run.c:829)
sys bpf (kernel/bpf/syscall.c:4804)
do syscall 64 (arch/x86/entry/syscall 64.c:94)
entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121)
Fall back to btf df show() when the resolved type has no show op; it
emits the "" placeholder already used for kinds like
FWD and FUNC. bpf snprintf btf() then returns the length as usual.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux