GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel BPF: bpf_btf_find_by_name_kind() can sleep in softirq context and install an fd into the interrupted task

UnscoredCVE-2026-98046Kernel, userspace & hypervisorcurated

Impact

When the helper finds a type in module BTF it returns a new BTF object fd via __btf_new_fd(), which reaches anon_inode_getfd() and can sleep while allocating or growing the task fd table. Because the prototype did not set might_sleep, the verifier allowed the helper in non-sleepable contexts such as BPF timer callbacks, so the allocation could sleep in softirq context and the resulting fd land in whatever task happened to be interrupted - a sleep-in-atomic bug plus an fd installed in an unrelated process. Practical effect on a GPU node is host instability and confused file descriptor ownership in a system agent, not tenant escape. Only programs loaded by a privileged BPF user can reach it.

Who can reach it

Local, privileged: requires the ability to load a BPF program that calls this helper from a timer or other non-sleepable context (CAP_BPF/CAP_SYS_ADMIN).

What to do

Update to a stable kernel where the helper is marked sleepable, which keeps calls from the main body of a sleepable syscall program while rejecting them from non-sleepable regions. Applying it means a node reboot; fold it into the regular kernel update window rather than an emergency one. No separate configuration mitigation beyond restricting who may load BPF programs.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.