Database/Kernel, userspace & hypervisor
Linux kernel BPF: a key-less BTF hash map can be created and reading it through bpffs NULL-derefs
Impact
map_check_btf() defers the key-less BTF decision to a map's ->map_check_btf callback. Hash maps used to have none, so btf_key_type_id == 0 was rejected outright; once htab and rhtab gained a callback to register a dtor, neither of which inspects the key, a key-less hash map began passing validation. Reading that map back through bpffs feeds key type_id 0 into btf_type_seq_show(), kind_ops[BTF_KIND_UNKN] is NULL, and btf_type_show() dereferences it - a kernel crash from a plain pread() on a bpffs file. On a GPU node that is an unplanned reboot and a lost job; reaching it needs BPF map creation privilege, so the exposure is through system agents, not tenant pods.
Who can reach it
Local, privileged: requires creating a BPF hash map with a key-less BTF (CAP_BPF/CAP_SYS_ADMIN) and then reading it via bpffs. Anyone able to read the pinned bpffs file can trigger the crash once such a map exists.
What to do
Update to a stable kernel that rejects a key-less BTF in htab_map_check_btf() and rhtab_map_check_btf(), restoring the previous behaviour. Requires a node reboot after drain. No separate mitigation beyond limiting who can create BPF maps and who can read bpffs mounts.
References
Related entries
- Linux kernel net/rds: a shutdown consuming a racing drop leaves an accepted socket wedged and never torn downCVE-2026-98068 · Linux kernel net/rds (rds_conn_shutdown() consuming a concurrent RDS_CONN_ERROR drop)Unscored
- Linux kernel net/rds: a blanket cp_flags store in the connection reset races atomic bitops and discards updatesCVE-2026-98071 · Linux kernel net/rds (rds_conn_path_reset() plain store to cp_flags)Unscored
- Linux kernel net/rds: a missing barrier in release_in_xmit() loses the wake-up and strands the RDS shutdown workerCVE-2026-98072 · Linux kernel net/rds (release_in_xmit() missing barrier before the wake-up check)Unscored
- Linux kernel BPF: a BPF_PSEUDO_FUNC load of the main program is never relocated, leaving a call to a bogus addressCVE-2026-98075 · Linux kernel BPF verifier (BPF_PSEUDO_FUNC reference to the main program)Unscored
- Linux kernel mpt3sas: NUMA_NO_NODE from dev_to_node() causes an out-of-bounds node_to_cpumask_map readCVE-2026-98088 · Linux kernel mpt3sas (_base_assign_reply_queues() NUMA node lookup)Unscored
- Linux kernel mpi3mr: error path in mpi3mr_sas_port_add() leaks a target device referenceCVE-2026-98128 · Linux kernel mpi3mr (target device refcount leak in mpi3mr_sas_port_add())Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.