PT-2026-98728 · Linux · Linux
CVE-2026-98065
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject key-less BTF for hash maps
map check btf() allows a key-less BTF (btf key type id == 0) only for
maps that have a ->map check btf callback, and leaves the actual
decision to that callback. Hash maps used to have no ->map check btf,
so a key-less BTF was rejected outright.
That changed when htab and rhtab gained a ->map check btf to register a
dtor - htab in commit 1df97a7453ee ("bpf: Register dtor for freeing
special fields") and rhtab in commit 6905f8601298 ("bpf: Allow special
fields in resizable hashtab"). Neither looks at the key, so a key-less
hash map now passes map check btf() and gets created. Reading it back
through bpffs feeds the key type id 0 into btf type seq show();
btf type by id() returns the void type, kind ops[BTF KIND UNKN] is NULL,
and btf type show() dereferences it:
RIP: 0010:btf type show+0x223/0x2e0 kernel/bpf/btf.c:8232
RSP: 0018:ffffc9000399f868 EFLAGS: 00010206
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000005 RSI: 0000000000000000 RDI: 0000000000000028
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: ffffc9000399f970 R11: 0000000000000001 R12: ffffffff9b96b140
R13: ffffc9000399f8e0 R14: ffff88803d393c00 R15: 0000000000000003
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000000000 CR3: 000000003d213000 CR4: 0000000000352ef0
DR0: 0000000039ae8f55 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Call Trace:
btf type seq show flags+0xca/0x120 kernel/bpf/btf.c:8250
htab map seq show elem+0x12e/0x350 kernel/bpf/hashtab.c:1669
map seq show+0x13d/0x1e0 kernel/bpf/inode.c:293
traverse.part.0.constprop.0+0x107/0x650 fs/seq file.c:112
traverse fs/seq file.c:99 [inline]
seq read iter+0x93f/0x1270 fs/seq file.c:196
seq read+0x344/0x4d0 fs/seq file.c:163
vfs read+0x1e4/0xb40 fs/read write.c:572
ksys pread64 fs/read write.c:764 [inline]
do sys pread64 fs/read write.c:772 [inline]
se sys pread64 fs/read write.c:769 [inline]
x64 sys pread64+0x1eb/0x250 fs/read write.c:769
do syscall x64 arch/x86/entry/syscall 64.c:61 [inline]
do syscall 64+0x123/0x790 arch/x86/entry/syscall 64.c:84
entry SYSCALL 64 after hwframe+0x77/0x7f
Reject a key-less BTF in htab map check btf() and rhtab map check btf(),
restoring the previous behavior.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux