CVE-2026-98064

Source
https://cve.org/CVERecord?id=CVE-2026-98064
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98064.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98064
Downstream
Published
2026-09-25T10:24:07Z
Modified
2026-09-26T03:48:32Z
Summary
bpf: Fix NULL-ptr-deref when showing a void BTF type
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix NULL-ptr-deref when showing a void BTF type

btf_modifier_show() resolves the modifier and then calls btf_type_ops(t)->show() unconditionally. For the void type (type_id 0, BTF_KIND_UNKN) kind_ops[] has no entry, so ->show is NULL.

A "const void" (a modifier resolving to void) cannot be a map key or value - map_check_btf() rejects it because void has no size - so the map dump path does not reach it. But bpf_snprintf_btf() takes a type_id straight from the BPF program, and passing such a "const void" from the vmlinux BTF NULL-derefs:

KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f] RIP: 0010:btf_modifier_show (kernel/bpf/btf.c:2914) Call Trace: btf_type_show (kernel/bpf/btf.c:8251) btf_type_snprintf_show (kernel/bpf/btf.c:8321) bpf_snprintf_btf (kernel/trace/bpf_trace.c:1047) bpf_prog_test_run_raw_tp (net/bpf/test_run.c:829) __sys_bpf (kernel/bpf/syscall.c:4804) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)

Fall back to btf_df_show() when the resolved type has no show op; it emits the "" placeholder already used for kinds like FWD and FUNC. bpf_snprintf_btf() then returns the length as usual.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98064.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c4d0bfb45068d853a478b9067a95969b1886a30f
Fixed
717abdfd1d559d01fdd102023f0a990fb0437240
Fixed
98f1cb95221332139acf514350ae2cae3b8656c5
Fixed
5324f4e75ff6e9c2ca2e267c5f34f0937f9d0ac9
Fixed
4ea508b9ebd78bce7f212166d2e2cba66b875f08

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98064.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98064.json"