Skip to main content
Vulnerability Database/CVE-2026-98063

CVE-2026-98063: Linux Kernel Use-After-Free Vulnerability

CVE-2026-98063 is a use-after-free vulnerability in the Linux kernel's BPF subsystem that causes NULL pointer dereference in btf_var_show(). This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-98063 Overview

CVE-2026-98063 is a NULL pointer dereference vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem. The flaw resides in the btf_var_show() function within kernel/bpf/btf.c. It occurs when a BPF program passes the type_id of a BTF_KIND_VAR from the vmlinux base BTF to bpf_snprintf_btf(). The function unconditionally calls btf_type_id_resolve(), which dereferences btf->resolved_ids. That pointer is NULL for base BTF because base BTF is not resolved during parsing, triggering a kernel crash.

Critical Impact

Local users invoking BPF syscalls can trigger a kernel NULL pointer dereference, causing a denial-of-service condition through kernel panic.

Affected Products

  • Linux kernel versions containing the vulnerable btf_var_show() implementation
  • Systems with BPF syscall access enabled for unprivileged or privileged users
  • Distributions shipping the vmlinux BTF used by bpf_snprintf_btf()

Discovery Timeline

  • 2026-09-25 - CVE-2026-98063 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98063

Vulnerability Analysis

The vulnerability is a NULL pointer dereference [CWE-476] in the kernel's BPF Type Format (BTF) rendering code path. When a BPF program invokes bpf_snprintf_btf() to format a variable using a type_id referencing a BTF_KIND_VAR entry in the vmlinux base BTF, execution reaches btf_var_show() in kernel/bpf/btf.c. That function calls btf_type_id_resolve() without first validating btf->resolved_ids.

Base BTF, such as the vmlinux BTF, does not populate resolved_ids during parsing. The dereference therefore reads from an invalid address. KASAN reports the fault as a probable user-memory-access in range [0x46638-0x4663f], with the crashing instruction at btf_var_show (kernel/bpf/btf.c:2929).

The call stack shows the panic propagating from btf_var_show through btf_type_show, btf_type_snprintf_show, bpf_snprintf_btf, bpf_prog_test_run_raw_tp, and the bpf() syscall entry point.

Root Cause

The sibling function btf_modifier_show() already guards access with if (btf->resolved_ids), but btf_var_show() lacks the equivalent check. The fix resolves the variable's type directly with btf_type_skip_modifiers() when resolved_ids is NULL, mirroring btf_modifier_show() behavior.

Attack Vector

A local attacker with the ability to load or run BPF programs can construct a program that passes a BTF_KIND_VAR type ID from vmlinux BTF into bpf_snprintf_btf(). Executing the program through BPF_PROG_TEST_RUN triggers the NULL dereference and crashes the kernel. The attack requires BPF syscall access, which is typically gated by CAP_BPF or CAP_SYS_ADMIN on modern kernels. The vulnerability is described in the upstream commits referenced in the kernel git log.

Detection Methods for CVE-2026-98063

Indicators of Compromise

  • Kernel panic logs or KASAN reports referencing btf_var_show at kernel/bpf/btf.c:2929
  • Call traces including bpf_snprintf_btf, btf_type_snprintf_show, and bpf_prog_test_run_raw_tp
  • Unexpected system reboots on hosts following execution of untrusted BPF programs

Detection Strategies

  • Audit kernel ring buffer (dmesg) for NULL-ptr-deref faults originating in BPF code paths
  • Monitor bpf() syscall activity, specifically BPF_PROG_LOAD and BPF_PROG_TEST_RUN commands from non-system accounts
  • Correlate crash dumps with recent BPF program loads using auditd rules on the bpf syscall

Monitoring Recommendations

  • Enable kernel crash collection via kdump to capture evidence of exploitation attempts
  • Track processes invoking bpf() with BPF_PROG_TEST_RUN and alert on anomalous frequency
  • Review which users or containers hold CAP_BPF or CAP_SYS_ADMIN and reduce the surface where possible

How to Mitigate CVE-2026-98063

Immediate Actions Required

  • Apply the upstream kernel patches to all affected stable branches
  • Restrict BPF syscall access by removing CAP_BPF and CAP_SYS_ADMIN from untrusted users and containers
  • Set kernel.unprivileged_bpf_disabled=1 if not already enforced

Patch Information

The fix adds a NULL check for btf->resolved_ids in btf_var_show() and falls back to btf_type_skip_modifiers() when the base BTF is unresolved. The patch is distributed across the following stable commits: 5403a38, ca08626, e472ae0, and ea383b3.

Workarounds

  • Disable unprivileged BPF program loading using the kernel.unprivileged_bpf_disabled sysctl
  • Use seccomp profiles to block the bpf() syscall for containerized workloads that do not require it
  • Remove CAP_BPF and CAP_PERFMON from container runtime defaults where feasible
bash
# Configuration example
# Disable unprivileged BPF at runtime
sysctl -w kernel.unprivileged_bpf_disabled=1

# Persist across reboots
echo 'kernel.unprivileged_bpf_disabled=1' | sudo tee /etc/sysctl.d/99-bpf-hardening.conf

# Verify current setting
sysctl kernel.unprivileged_bpf_disabled

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.