Database/Kernel, userspace & hypervisor
Linux kernel BPF: rendering a "const void" BTF type through bpf_snprintf_btf() NULL-derefs a missing show op
Impact
btf_modifier_show() resolved the modifier and then called btf_type_ops(t)->show() unconditionally, but the void type (type_id 0, BTF_KIND_UNKN) has no kind_ops entry, so ->show is NULL. Map key and value paths cannot reach it because void has no size, but bpf_snprintf_btf() takes a type_id straight from the BPF program, so passing a "const void" from the vmlinux BTF crashes the kernel. On a GPU host that is an unplanned node loss - the job on the GPU dies and the node needs a reboot - and the trigger is in a system agent, since only a privileged BPF loader can reach the path. Distinct from the btf_var_show() NULL deref fixed separately: different function, different missing guard, different fix.
Who can reach it
Local, privileged: requires the ability to load and run a BPF program calling bpf_snprintf_btf() with an attacker-chosen type_id (CAP_BPF/CAP_SYS_ADMIN).
What to do
Update to a stable kernel with the fix, which falls back to btf_df_show() when the resolved type has no show op, emitting the existing "<unsupported kind:N>" placeholder. Requires draining the node and rebooting into the patched kernel. No configuration-level mitigation other than restricting BPF program loading.
References
Related entries
- Linux kernel BPF: a key-less BTF hash map can be created and reading it through bpffs NULL-derefsCVE-2026-98065 · Linux kernel BPF hash maps (htab/rhtab map_check_btf key-less BTF)Unscored
- Linux kernel net/rds: a shutdown consuming a racing drop leaves an accepted socket wedged and never torn downCVE-2026-98068 · Linux kernel net/rds (rds_conn_shutdown() consuming a concurrent RDS_CONN_ERROR drop)Unscored
- Linux kernel net/rds: a blanket cp_flags store in the connection reset races atomic bitops and discards updatesCVE-2026-98071 · Linux kernel net/rds (rds_conn_path_reset() plain store to cp_flags)Unscored
- Linux kernel net/rds: a missing barrier in release_in_xmit() loses the wake-up and strands the RDS shutdown workerCVE-2026-98072 · Linux kernel net/rds (release_in_xmit() missing barrier before the wake-up check)Unscored
- Linux kernel BPF: a BPF_PSEUDO_FUNC load of the main program is never relocated, leaving a call to a bogus addressCVE-2026-98075 · Linux kernel BPF verifier (BPF_PSEUDO_FUNC reference to the main program)Unscored
- Linux kernel mpt3sas: NUMA_NO_NODE from dev_to_node() causes an out-of-bounds node_to_cpumask_map readCVE-2026-98088 · Linux kernel mpt3sas (_base_assign_reply_queues() NUMA node lookup)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.