Database/Kernel, userspace & hypervisor
Linux kernel BPF verifier (bpf_loop nr_loops argument type): bpf_loop() declared nr_loops as ARG_ANYTHING, so a
Impact
bpf_loop() declared nr_loops as ARG_ANYTHING, so a privileged program could pass a pointer-valued R1 through check_func_arg(). The verifier marks that register precise to bound callback simulation, precision backtracking only accepts scalars, and the mismatch triggers the "backtracking misuse" warning - which on a kernel built or booted with panic_on_warn takes the whole node down. On a GPU node the cost is not the crash itself but the drain: an in-flight training job dies with it and the node has to be rebooted and re-attested before it takes work again. Reachable only by whoever can load BPF programs, so the realistic trigger is a buggy or hostile observability/CNI agent rather than a tenant pod.
Who can reach it
Local, privileged: requires the ability to load a BPF program (CAP_BPF/CAP_SYS_ADMIN in the init namespace). Not reachable by an unprivileged tenant pod without BPF access.
What to do
Update to a stable kernel carrying the fix, which introduces ARG_SCALAR and uses it for bpf_loop()'s nr_loops so the pointer is rejected during generic argument validation. Requires a node reboot, so schedule it with the next kernel maintenance pass. Interim mitigation: do not boot GPU nodes with panic_on_warn, and keep BPF loading restricted to trusted system agents.
References
Related entries
- Linux kernel BPF: bpf_btf_find_by_name_kind() can sleep in softirq context and install an fd into the interrupted taskCVE-2026-98046 · Linux kernel BPF helper bpf_btf_find_by_name_kind() (missing sleepable annotation)Unscored
- Linux kernel BPF: bpf_snprintf_btf() on a BTF_KIND_VAR from base BTF NULL-derefs in btf_var_show()CVE-2026-98063 · Linux kernel BPF BTF display (btf_var_show() unguarded resolved_ids deref)Unscored
- Linux kernel BPF: rendering a "const void" BTF type through bpf_snprintf_btf() NULL-derefs a missing show opCVE-2026-98064 · Linux kernel BPF BTF display (btf_modifier_show() missing show op for void)Unscored
- Linux kernel BPF: a key-less BTF hash map can be created and reading it through bpffs NULL-derefsCVE-2026-98065 · Linux kernel BPF hash maps (htab/rhtab map_check_btf key-less BTF)Unscored
- Linux kernel net/rds: a shutdown consuming a racing drop leaves an accepted socket wedged and never torn downCVE-2026-98068 · Linux kernel net/rds (rds_conn_shutdown() consuming a concurrent RDS_CONN_ERROR drop)Unscored
- Linux kernel net/rds: a blanket cp_flags store in the connection reset races atomic bitops and discards updatesCVE-2026-98071 · Linux kernel net/rds (rds_conn_path_reset() plain store to cp_flags)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.