Database/Kernel, userspace & hypervisor
Linux kernel BPF: tp_btf program dereferencing SEND_SIG_NOINFO can panic the node
Impact
The signal_generate and signal_deliver tracepoints declare their siginfo argument as a struct kernel_siginfo pointer, so btf_ctx_access() treated it as a trusted pointer for tp_btf programs. Signal delivery also passes the sentinel values SEND_SIG_NOINFO (0) and SEND_SIG_PRIV (1) in that slot, so a BPF program attached to these tracepoints can dereference a non-pointer and fault the kernel; because signal_generate can run from timer interrupt context, the fault becomes a panic rather than a recoverable oops. On a GPU node that means an unplanned crash of every tenant sharing the box and a cold restart of long-running training or serving jobs, with the GPU state lost. It matters most on fleets where observability or security agents load BPF tracing programs, since the dangerous attach is an ordinary profiling action rather than an obvious exploit.
Who can reach it
Local, and requires the privilege to load and attach a tp_btf BPF program (effectively CAP_BPF/CAP_SYS_ADMIN or root in the host namespace). Unprivileged tenants in a normal container cannot reach it; an operator's own tracing tooling or a privileged DaemonSet can.
What to do
Pick up the stable kernel commits that record both tracepoints in raw_tp_null_args[] and mark argument one as a scalar, then drain and reboot each node - there is no live mitigation for an in-tree verifier fix. Until the kernel is updated, the practical mitigation is to not attach tp_btf programs to signal_generate or signal_deliver and to keep BPF-load privilege off tenant workloads. The record names no vendor-fixed version, only the git commits.
References
Related entries
- Linux kernel nvmet-rdma: queue and IB resources leak when the connect backlog is exceededCVE-2026-98152 · Linux kernel nvmet-rdma (NVMe-oF RDMA target connect path)Medium
- AMD SEV-ES (CacheWarp): CacheWarp: INVD lets a malicious hypervisor revert SEV-ES guest memory writes, breaking guestCVE-2023-20592 · AMD SEV-ES (CacheWarp)Medium
- Linux kernel (drivers/pci): When the kernel coalesces two adjacent host-bridge apertures it invalidates the absorbedCVE-2023-53814 · Linux kernel (drivers/pci)Medium
- AMD SEV-SNP (BadRAM): BadRAM: improper validation of DIMM SPD metadata lets an attacker with physical access or ring0CVE-2024-21944 · AMD SEV-SNP (BadRAM)Medium
- OpenSSL QUIC: missing connection-level flow control lets a peer force ~100MB of heap per connectionCVE-2026-75804 · OpenSSL QUIC stack (connection-level flow control)Medium
- OpenSSL CMP client: NULL dereference when revoking a certificate by PKCS#10 CSRCVE-2026-75805 · OpenSSL CMP client (revocation-by-CSR response handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.