GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel BPF: a BPF_PSEUDO_FUNC load of the main program is never relocated, leaving a call to a bogus address

UnscoredCVE-2026-98075Kernel, userspace & hypervisorcurated

Impact

jit_subprogs() rewrites BPF_PSEUDO_FUNC loads into real function addresses, but it only runs when the program has more than one subprogram. A program that takes the address of its own main function and hands it to something like bpf_timer_set_callback() therefore keeps an unrelocated value, and the kernel later calls through a bogus address. That is kernel control-flow corruption rather than a plain crash, and on a GPU node a kernel fault means the node drops its running job and has to be rebooted. The path is only open to a privileged BPF loader, so the realistic source is a system agent that loads programs, not a tenant workload.

Who can reach it

Local, privileged: requires loading a BPF program containing a BPF_PSEUDO_FUNC reference to its own main subprogram (CAP_BPF/CAP_SYS_ADMIN). No unprivileged or remote path.

What to do

Update to a stable kernel where the verifier rejects BPF_PSEUDO_FUNC loads for the main subprogram outright. Applying it requires draining the node and rebooting into the patched kernel. Until then, keep BPF program loading restricted to trusted components; there is no runtime mitigation in the advisory.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.