Database/Kernel, userspace & hypervisor
Linux kernel BPF: bpf_btf_find_by_name_kind() can sleep in softirq context and install an fd into the interrupted task
Impact
When the helper finds a type in module BTF it returns a new BTF object fd via __btf_new_fd(), which reaches anon_inode_getfd() and can sleep while allocating or growing the task fd table. Because the prototype did not set might_sleep, the verifier allowed the helper in non-sleepable contexts such as BPF timer callbacks, so the allocation could sleep in softirq context and the resulting fd land in whatever task happened to be interrupted - a sleep-in-atomic bug plus an fd installed in an unrelated process. Practical effect on a GPU node is host instability and confused file descriptor ownership in a system agent, not tenant escape. Only programs loaded by a privileged BPF user can reach it.
Who can reach it
Local, privileged: requires the ability to load a BPF program that calls this helper from a timer or other non-sleepable context (CAP_BPF/CAP_SYS_ADMIN).
What to do
Update to a stable kernel where the helper is marked sleepable, which keeps calls from the main body of a sleepable syscall program while rejecting them from non-sleepable regions. Applying it means a node reboot; fold it into the regular kernel update window rather than an emergency one. No separate configuration mitigation beyond restricting who may load BPF programs.
References
Related entries
- Linux kernel BPF: bpf_snprintf_btf() on a BTF_KIND_VAR from base BTF NULL-derefs in btf_var_show()CVE-2026-98063 · Linux kernel BPF BTF display (btf_var_show() unguarded resolved_ids deref)Unscored
- Linux kernel BPF: rendering a "const void" BTF type through bpf_snprintf_btf() NULL-derefs a missing show opCVE-2026-98064 · Linux kernel BPF BTF display (btf_modifier_show() missing show op for void)Unscored
- Linux kernel BPF: a key-less BTF hash map can be created and reading it through bpffs NULL-derefsCVE-2026-98065 · Linux kernel BPF hash maps (htab/rhtab map_check_btf key-less BTF)Unscored
- Linux kernel net/rds: a shutdown consuming a racing drop leaves an accepted socket wedged and never torn downCVE-2026-98068 · Linux kernel net/rds (rds_conn_shutdown() consuming a concurrent RDS_CONN_ERROR drop)Unscored
- Linux kernel net/rds: a blanket cp_flags store in the connection reset races atomic bitops and discards updatesCVE-2026-98071 · Linux kernel net/rds (rds_conn_path_reset() plain store to cp_flags)Unscored
- Linux kernel net/rds: a missing barrier in release_in_xmit() loses the wake-up and strands the RDS shutdown workerCVE-2026-98072 · Linux kernel net/rds (release_in_xmit() missing barrier before the wake-up check)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.