Database/Kernel, userspace & hypervisor
Linux kernel BPF: bpf_snprintf_btf() on a BTF_KIND_VAR from base BTF NULL-derefs in btf_var_show()
Impact
btf_var_show() called btf_type_id_resolve() unconditionally, dereferencing btf->resolved_ids, which is NULL for base BTF such as the vmlinux BTF that bpf_snprintf_btf() renders against - btf_modifier_show() guards for this, btf_var_show() did not. A BPF program that hands the type_id of a vmlinux BTF variable to bpf_snprintf_btf() therefore crashes the kernel. The exposure is a host crash on a node loaded with BPF tooling: the running training or inference job on that GPU node dies and the node needs a reboot. Requires BPF load privilege, so the realistic source is a faulty or malicious observability agent rather than a tenant workload.
Who can reach it
Local, privileged: requires the ability to load and run a BPF program calling bpf_snprintf_btf() (CAP_BPF/CAP_SYS_ADMIN). No remote or unprivileged path.
What to do
Update to a stable kernel carrying the fix, which resolves the variable's type with btf_type_skip_modifiers() when resolved_ids is NULL, mirroring btf_modifier_show(). Requires a node reboot after drain. No vendor-supplied mitigation; in the meantime limit BPF program loading to trusted system components.
References
Related entries
- Linux kernel BPF: rendering a "const void" BTF type through bpf_snprintf_btf() NULL-derefs a missing show opCVE-2026-98064 · Linux kernel BPF BTF display (btf_modifier_show() missing show op for void)Unscored
- Linux kernel BPF: a key-less BTF hash map can be created and reading it through bpffs NULL-derefsCVE-2026-98065 · Linux kernel BPF hash maps (htab/rhtab map_check_btf key-less BTF)Unscored
- Linux kernel net/rds: a shutdown consuming a racing drop leaves an accepted socket wedged and never torn downCVE-2026-98068 · Linux kernel net/rds (rds_conn_shutdown() consuming a concurrent RDS_CONN_ERROR drop)Unscored
- Linux kernel net/rds: a blanket cp_flags store in the connection reset races atomic bitops and discards updatesCVE-2026-98071 · Linux kernel net/rds (rds_conn_path_reset() plain store to cp_flags)Unscored
- Linux kernel net/rds: a missing barrier in release_in_xmit() loses the wake-up and strands the RDS shutdown workerCVE-2026-98072 · Linux kernel net/rds (release_in_xmit() missing barrier before the wake-up check)Unscored
- Linux kernel BPF: a BPF_PSEUDO_FUNC load of the main program is never relocated, leaving a call to a bogus addressCVE-2026-98075 · Linux kernel BPF verifier (BPF_PSEUDO_FUNC reference to the main program)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.