Database/Kernel, userspace & hypervisor
Linux kernel BPF: a BPF_PSEUDO_FUNC load of the main program is never relocated, leaving a call to a bogus address
Impact
jit_subprogs() rewrites BPF_PSEUDO_FUNC loads into real function addresses, but it only runs when the program has more than one subprogram. A program that takes the address of its own main function and hands it to something like bpf_timer_set_callback() therefore keeps an unrelocated value, and the kernel later calls through a bogus address. That is kernel control-flow corruption rather than a plain crash, and on a GPU node a kernel fault means the node drops its running job and has to be rebooted. The path is only open to a privileged BPF loader, so the realistic source is a system agent that loads programs, not a tenant workload.
Who can reach it
Local, privileged: requires loading a BPF program containing a BPF_PSEUDO_FUNC reference to its own main subprogram (CAP_BPF/CAP_SYS_ADMIN). No unprivileged or remote path.
What to do
Update to a stable kernel where the verifier rejects BPF_PSEUDO_FUNC loads for the main subprogram outright. Applying it requires draining the node and rebooting into the patched kernel. Until then, keep BPF program loading restricted to trusted components; there is no runtime mitigation in the advisory.
References
Related entries
- Linux kernel mpt3sas: NUMA_NO_NODE from dev_to_node() causes an out-of-bounds node_to_cpumask_map readCVE-2026-98088 · Linux kernel mpt3sas (_base_assign_reply_queues() NUMA node lookup)Unscored
- Linux kernel mpi3mr: error path in mpi3mr_sas_port_add() leaks a target device referenceCVE-2026-98128 · Linux kernel mpi3mr (target device refcount leak in mpi3mr_sas_port_add())Unscored
- Linux kernel mpi3mr: NULL dereference and sas_port leak when SAS port allocation failsCVE-2026-98129 · Linux kernel mpi3mr (Broadcom tri-mode SAS/SATA/NVMe HBA driver)Unscored
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeCVE-2026-98163 · Linux kernel cgroup task iterator (css_task_iter_next over dying_tasks)Unscored
- Linux KVM x86/mmu: write tracking checked in one address space only, reaching a kernel BUGCVE-2026-98164 · Linux kernel KVM x86/mmu (kvm_gfn_is_write_tracked across address spaces)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.