Skip to main content
Vulnerability Database/CVE-2026-98062

CVE-2026-98062: Linux Kernel BPF Privilege Escalation Flaw

CVE-2026-98062 is a privilege escalation vulnerability in the Linux kernel BPF subsystem that allows unauthorized access through signal tracepoint exploitation. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-98062 Overview

CVE-2026-98062 is a Linux kernel vulnerability in the Berkeley Packet Filter (BPF) subsystem. The flaw affects the signal_generate and signal_deliver tracepoints, which declare their info argument as a struct kernel_siginfo pointer. The btf_ctx_access() function treats this argument as a trusted pointer for tp_btf programs. However, signal delivery also uses SEND_SIG_NOINFO (value 0) and SEND_SIG_PRIV (value 1) as sentinel scalar values rather than pointers. A tp_btf program dereferencing either value triggers a kernel fault.

Critical Impact

An unprivileged BPF program attaching to signal tracepoints can crash the kernel. Because signal_generate runs from timer interrupt context, the fault escalates into a full kernel panic.

Affected Products

  • Linux kernel versions containing the vulnerable signal tracepoint BPF context handling
  • Systems running tp_btf BPF programs attached to signal_generate or signal_deliver
  • Kernel builds prior to the fixes referenced in the upstream stable commits

Discovery Timeline

  • 2026-09-25 - CVE-2026-98062 published to the National Vulnerability Database (NVD)
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98062

Vulnerability Analysis

The vulnerability resides in the BPF type verifier's handling of signal tracepoint arguments. The signal_generate and signal_deliver tracepoints expose an info parameter typed as struct kernel_siginfo *. The BPF Type Format (BTF) context-access check treats pointer-typed arguments as trusted, allowing BPF programs to dereference them directly or pass them to helpers that read kernel memory.

The kernel signal subsystem overloads this argument with two magic scalar values. SEND_SIG_NOINFO is defined as 0 and SEND_SIG_PRIV is defined as 1. Neither value refers to valid memory. When a tp_btf BPF program attached to either tracepoint dereferences info, the kernel attempts to read from address 0 or address 1 and faults.

Signal generation frequently occurs from timer interrupt context. Faults raised in that context cannot be recovered, so the kernel panics. The result is a denial of service reachable by any user capable of loading a tp_btf program.

Root Cause

The root cause is a type system mismatch between the BPF verifier's view of the tracepoint context and the actual runtime semantics. The verifier trusts the declared pointer type, while the signal subsystem passes magic scalar sentinels that look like pointers but are not. This produces a Null Pointer Dereference condition at the kernel level [CWE-476].

Attack Vector

An attacker loads a tp_btf BPF program that attaches to signal_generate or signal_deliver and dereferences the info argument, or passes it to a helper that reads from the pointer. When any signal is sent using SEND_SIG_NOINFO or SEND_SIG_PRIV, the dereference faults. Because signal_generate is reachable from timer interrupt context, the fault produces a kernel panic rather than a recoverable oops. The upstream fix records both tracepoints in raw_tp_null_args[] and marks argument one as a non-pointer, preserving scalar access while rejecting pointer dereferences and helper-mediated reads.

Detection Methods for CVE-2026-98062

Indicators of Compromise

  • Unexpected kernel panics or oops messages referencing the signal subsystem, signal_generate, or signal_deliver call paths
  • Crash dumps showing faulting addresses of 0x0 or 0x1 inside BPF-executed code
  • bpf() syscall activity loading tp_btf programs that attach to signal tracepoints from non-root or minimally privileged contexts

Detection Strategies

  • Audit loaded BPF programs with bpftool prog show and inspect any program attached to signal tracepoints for dereferences of the info argument
  • Monitor kernel ring buffer (dmesg) for faults originating in interrupt context tied to BPF execution
  • Correlate BPF program load events with subsequent kernel panics occurring within short time windows

Monitoring Recommendations

  • Enable auditd rules for the bpf() syscall and record the loading UID, program type, and attach target
  • Forward kernel crash telemetry and kdump output to centralized logging for post-mortem analysis
  • Track kernel version inventory to confirm patch deployment across all Linux hosts

How to Mitigate CVE-2026-98062

Immediate Actions Required

  • Apply the upstream stable kernel patches referenced in the Linux kernel git commits as soon as vendor builds are available
  • Restrict the CAP_BPF and CAP_SYS_ADMIN capabilities to trusted service accounts to limit who can load tp_btf programs
  • Set kernel.unprivileged_bpf_disabled=1 where operational requirements permit

Patch Information

The fix is distributed across three upstream commits: Linux Kernel Commit 0e78cb24, Linux Kernel Commit 77515ab1, and Linux Kernel Commit d2eaea35. The patch records both signal tracepoints in raw_tp_null_args[] and marks the info argument as a non-pointer, so the BPF verifier rejects direct dereferences and helper-mediated pointer use while retaining scalar access to the cookie value.

Workarounds

  • Disable unprivileged BPF program loading by setting sysctl kernel.unprivileged_bpf_disabled=1 and persisting the value in /etc/sysctl.d/
  • Use Linux Security Modules such as SELinux or AppArmor to deny the bpf capability to workloads that do not require it
  • Remove or deny-list tp_btf attachments to signal_generate and signal_deliver through runtime admission controls where available
bash
# Disable unprivileged BPF program loading
sudo sysctl -w kernel.unprivileged_bpf_disabled=1
echo 'kernel.unprivileged_bpf_disabled=1' | sudo tee /etc/sysctl.d/99-bpf-hardening.conf

# Inventory existing BPF programs and their attach points
sudo bpftool prog show
sudo bpftool link show

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.