CVE-2026-98063 Overview
CVE-2026-98063 is a NULL pointer dereference vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem. The flaw resides in the btf_var_show() function within kernel/bpf/btf.c. It occurs when a BPF program passes the type_id of a BTF_KIND_VAR from the vmlinux base BTF to bpf_snprintf_btf(). The function unconditionally calls btf_type_id_resolve(), which dereferences btf->resolved_ids. That pointer is NULL for base BTF because base BTF is not resolved during parsing, triggering a kernel crash.
Critical Impact
Local users invoking BPF syscalls can trigger a kernel NULL pointer dereference, causing a denial-of-service condition through kernel panic.
Affected Products
- Linux kernel versions containing the vulnerable btf_var_show() implementation
- Systems with BPF syscall access enabled for unprivileged or privileged users
- Distributions shipping the vmlinux BTF used by bpf_snprintf_btf()
Discovery Timeline
- 2026-09-25 - CVE-2026-98063 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98063
Vulnerability Analysis
The vulnerability is a NULL pointer dereference [CWE-476] in the kernel's BPF Type Format (BTF) rendering code path. When a BPF program invokes bpf_snprintf_btf() to format a variable using a type_id referencing a BTF_KIND_VAR entry in the vmlinux base BTF, execution reaches btf_var_show() in kernel/bpf/btf.c. That function calls btf_type_id_resolve() without first validating btf->resolved_ids.
Base BTF, such as the vmlinux BTF, does not populate resolved_ids during parsing. The dereference therefore reads from an invalid address. KASAN reports the fault as a probable user-memory-access in range [0x46638-0x4663f], with the crashing instruction at btf_var_show (kernel/bpf/btf.c:2929).
The call stack shows the panic propagating from btf_var_show through btf_type_show, btf_type_snprintf_show, bpf_snprintf_btf, bpf_prog_test_run_raw_tp, and the bpf() syscall entry point.
Root Cause
The sibling function btf_modifier_show() already guards access with if (btf->resolved_ids), but btf_var_show() lacks the equivalent check. The fix resolves the variable's type directly with btf_type_skip_modifiers() when resolved_ids is NULL, mirroring btf_modifier_show() behavior.
Attack Vector
A local attacker with the ability to load or run BPF programs can construct a program that passes a BTF_KIND_VAR type ID from vmlinux BTF into bpf_snprintf_btf(). Executing the program through BPF_PROG_TEST_RUN triggers the NULL dereference and crashes the kernel. The attack requires BPF syscall access, which is typically gated by CAP_BPF or CAP_SYS_ADMIN on modern kernels. The vulnerability is described in the upstream commits referenced in the kernel git log.
Detection Methods for CVE-2026-98063
Indicators of Compromise
- Kernel panic logs or KASAN reports referencing btf_var_show at kernel/bpf/btf.c:2929
- Call traces including bpf_snprintf_btf, btf_type_snprintf_show, and bpf_prog_test_run_raw_tp
- Unexpected system reboots on hosts following execution of untrusted BPF programs
Detection Strategies
- Audit kernel ring buffer (dmesg) for NULL-ptr-deref faults originating in BPF code paths
- Monitor bpf() syscall activity, specifically BPF_PROG_LOAD and BPF_PROG_TEST_RUN commands from non-system accounts
- Correlate crash dumps with recent BPF program loads using auditd rules on the bpf syscall
Monitoring Recommendations
- Enable kernel crash collection via kdump to capture evidence of exploitation attempts
- Track processes invoking bpf() with BPF_PROG_TEST_RUN and alert on anomalous frequency
- Review which users or containers hold CAP_BPF or CAP_SYS_ADMIN and reduce the surface where possible
How to Mitigate CVE-2026-98063
Immediate Actions Required
- Apply the upstream kernel patches to all affected stable branches
- Restrict BPF syscall access by removing CAP_BPF and CAP_SYS_ADMIN from untrusted users and containers
- Set kernel.unprivileged_bpf_disabled=1 if not already enforced
Patch Information
The fix adds a NULL check for btf->resolved_ids in btf_var_show() and falls back to btf_type_skip_modifiers() when the base BTF is unresolved. The patch is distributed across the following stable commits: 5403a38, ca08626, e472ae0, and ea383b3.
Workarounds
- Disable unprivileged BPF program loading using the kernel.unprivileged_bpf_disabled sysctl
- Use seccomp profiles to block the bpf() syscall for containerized workloads that do not require it
- Remove CAP_BPF and CAP_PERFMON from container runtime defaults where feasible
# Configuration example
# Disable unprivileged BPF at runtime
sysctl -w kernel.unprivileged_bpf_disabled=1
# Persist across reboots
echo 'kernel.unprivileged_bpf_disabled=1' | sudo tee /etc/sysctl.d/99-bpf-hardening.conf
# Verify current setting
sysctl kernel.unprivileged_bpf_disabled
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.