CVE-2026-98064 Overview
CVE-2026-98064 is a NULL pointer dereference vulnerability in the Linux kernel's Berkeley Packet Filter (BPF) subsystem. The flaw resides in btf_modifier_show() within kernel/bpf/btf.c, which unconditionally invokes btf_type_ops(t)->show() after resolving a type modifier. For the void type (type_id 0, BTF_KIND_UNKN), the kind_ops[] table has no entry, so the ->show function pointer is NULL. Passing a const void type identifier from a BPF program through bpf_snprintf_btf() dereferences this NULL pointer in kernel context.
Critical Impact
A local user with BPF program load privileges can trigger a kernel NULL pointer dereference, causing a denial of service through kernel oops or panic.
Affected Products
- Linux kernel versions containing the vulnerable btf_modifier_show() implementation
- Systems with BPF subsystem enabled and BTF (BPF Type Format) support
- Distributions shipping kernels prior to the referenced stable patches
Discovery Timeline
- 2026-09-25 - CVE-2026-98064 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98064
Vulnerability Analysis
The vulnerability affects the BPF Type Format (BTF) display path used to render kernel data structures as strings. The btf_modifier_show() function in kernel/bpf/btf.c resolves type modifiers such as const, volatile, and restrict, then calls the resolved type's show operation. The function assumes every resolved type has a valid show operation handler registered.
For the void type, identified by type_id 0 and BTF_KIND_UNKN, no entry exists in the kind_ops[] dispatch table. This results in a NULL function pointer that the code dereferences without validation. The KASAN report confirms the crash address falls in the range [0x0000000000000028-0x000000000000002f], consistent with structure field access through a NULL pointer.
The map validation path blocks this condition because map_check_btf() rejects void as a map key or value, since void has no defined size. However, bpf_snprintf_btf() accepts a type_id parameter directly from an unprivileged BPF program and bypasses that safeguard.
Root Cause
The root cause is missing validation of the show function pointer before invocation. The kind_ops[] table lacks an entry for BTF_KIND_UNKN, and btf_modifier_show() does not check whether the resolved type's operation handler is NULL before calling it.
Attack Vector
A local attacker loads a BPF program that invokes the bpf_snprintf_btf() helper with a type_id referencing a const void type from the vmlinux BTF. The call chain traverses bpf_prog_test_run_raw_tp() through btf_type_snprintf_show() into btf_type_show(), reaching btf_modifier_show(). The NULL dereference triggers a kernel oops in the task context.
The upstream fix falls back to btf_df_show() when the resolved type has no show operation. This handler emits the <unsupported kind:N> placeholder already used for kinds such as FWD and FUNC, allowing bpf_snprintf_btf() to return the length normally. See the kernel patch commits for implementation details.
Detection Methods for CVE-2026-98064
Indicators of Compromise
- Kernel oops or panic messages referencing btf_modifier_show in the call trace
- KASAN reports showing NULL pointer dereference in kernel/bpf/btf.c around line 2914
- Unexpected process termination with BPF-related system call activity preceding the crash
Detection Strategies
- Monitor dmesg and /var/log/kern.log for kernel oops entries containing btf_modifier_show or btf_type_show symbols
- Audit bpf() syscall usage, particularly BPF_PROG_TEST_RUN operations invoking bpf_snprintf_btf
- Correlate kernel crash events with the UID of processes loading BPF programs
Monitoring Recommendations
- Enable kernel audit rules for bpf() syscall invocations by non-root users
- Collect kernel crash dumps using kdump for forensic analysis of exploitation attempts
- Track processes holding CAP_BPF or CAP_SYS_ADMIN capabilities and their BPF program load events
How to Mitigate CVE-2026-98064
Immediate Actions Required
- Apply the upstream kernel patches referenced in the stable tree commits as soon as distribution packages become available
- Restrict unprivileged BPF program loading by setting kernel.unprivileged_bpf_disabled=1 in /etc/sysctl.conf
- Audit which users and containers hold CAP_BPF or CAP_SYS_ADMIN and revoke where not required
Patch Information
The fix is distributed across multiple stable kernel branches. Reference the following commits: 4ea508b9ebd7, 5324f4e75ff6, 717abdfd1d55, and 98f1cb952213. The patches add a fallback to btf_df_show() when the resolved type lacks a show operation.
Workarounds
- Disable unprivileged BPF access system-wide using the kernel.unprivileged_bpf_disabled sysctl
- Enforce seccomp profiles on container workloads that block the bpf() syscall where not required
- Remove CAP_BPF from workload capability sets using Kubernetes securityContext or systemd unit directives
# Configuration example
# Disable unprivileged BPF program loading
sysctl -w kernel.unprivileged_bpf_disabled=1
echo 'kernel.unprivileged_bpf_disabled=1' >> /etc/sysctl.d/99-bpf-hardening.conf
# Verify setting
sysctl kernel.unprivileged_bpf_disabled
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.