Skip to main content
Vulnerability Database/CVE-2026-98064

CVE-2026-98064: Linux Kernel Use-After-Free Vulnerability

CVE-2026-98064 is a use-after-free flaw in the Linux kernel's BPF subsystem that causes NULL pointer dereference when handling void BTF types. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2026-98064 Overview

CVE-2026-98064 is a NULL pointer dereference vulnerability in the Linux kernel's Berkeley Packet Filter (BPF) subsystem. The flaw resides in btf_modifier_show() within kernel/bpf/btf.c, which unconditionally invokes btf_type_ops(t)->show() after resolving a type modifier. For the void type (type_id 0, BTF_KIND_UNKN), the kind_ops[] table has no entry, so the ->show function pointer is NULL. Passing a const void type identifier from a BPF program through bpf_snprintf_btf() dereferences this NULL pointer in kernel context.

Critical Impact

A local user with BPF program load privileges can trigger a kernel NULL pointer dereference, causing a denial of service through kernel oops or panic.

Affected Products

  • Linux kernel versions containing the vulnerable btf_modifier_show() implementation
  • Systems with BPF subsystem enabled and BTF (BPF Type Format) support
  • Distributions shipping kernels prior to the referenced stable patches

Discovery Timeline

  • 2026-09-25 - CVE-2026-98064 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98064

Vulnerability Analysis

The vulnerability affects the BPF Type Format (BTF) display path used to render kernel data structures as strings. The btf_modifier_show() function in kernel/bpf/btf.c resolves type modifiers such as const, volatile, and restrict, then calls the resolved type's show operation. The function assumes every resolved type has a valid show operation handler registered.

For the void type, identified by type_id 0 and BTF_KIND_UNKN, no entry exists in the kind_ops[] dispatch table. This results in a NULL function pointer that the code dereferences without validation. The KASAN report confirms the crash address falls in the range [0x0000000000000028-0x000000000000002f], consistent with structure field access through a NULL pointer.

The map validation path blocks this condition because map_check_btf() rejects void as a map key or value, since void has no defined size. However, bpf_snprintf_btf() accepts a type_id parameter directly from an unprivileged BPF program and bypasses that safeguard.

Root Cause

The root cause is missing validation of the show function pointer before invocation. The kind_ops[] table lacks an entry for BTF_KIND_UNKN, and btf_modifier_show() does not check whether the resolved type's operation handler is NULL before calling it.

Attack Vector

A local attacker loads a BPF program that invokes the bpf_snprintf_btf() helper with a type_id referencing a const void type from the vmlinux BTF. The call chain traverses bpf_prog_test_run_raw_tp() through btf_type_snprintf_show() into btf_type_show(), reaching btf_modifier_show(). The NULL dereference triggers a kernel oops in the task context.

The upstream fix falls back to btf_df_show() when the resolved type has no show operation. This handler emits the <unsupported kind:N> placeholder already used for kinds such as FWD and FUNC, allowing bpf_snprintf_btf() to return the length normally. See the kernel patch commits for implementation details.

Detection Methods for CVE-2026-98064

Indicators of Compromise

  • Kernel oops or panic messages referencing btf_modifier_show in the call trace
  • KASAN reports showing NULL pointer dereference in kernel/bpf/btf.c around line 2914
  • Unexpected process termination with BPF-related system call activity preceding the crash

Detection Strategies

  • Monitor dmesg and /var/log/kern.log for kernel oops entries containing btf_modifier_show or btf_type_show symbols
  • Audit bpf() syscall usage, particularly BPF_PROG_TEST_RUN operations invoking bpf_snprintf_btf
  • Correlate kernel crash events with the UID of processes loading BPF programs

Monitoring Recommendations

  • Enable kernel audit rules for bpf() syscall invocations by non-root users
  • Collect kernel crash dumps using kdump for forensic analysis of exploitation attempts
  • Track processes holding CAP_BPF or CAP_SYS_ADMIN capabilities and their BPF program load events

How to Mitigate CVE-2026-98064

Immediate Actions Required

  • Apply the upstream kernel patches referenced in the stable tree commits as soon as distribution packages become available
  • Restrict unprivileged BPF program loading by setting kernel.unprivileged_bpf_disabled=1 in /etc/sysctl.conf
  • Audit which users and containers hold CAP_BPF or CAP_SYS_ADMIN and revoke where not required

Patch Information

The fix is distributed across multiple stable kernel branches. Reference the following commits: 4ea508b9ebd7, 5324f4e75ff6, 717abdfd1d55, and 98f1cb952213. The patches add a fallback to btf_df_show() when the resolved type lacks a show operation.

Workarounds

  • Disable unprivileged BPF access system-wide using the kernel.unprivileged_bpf_disabled sysctl
  • Enforce seccomp profiles on container workloads that block the bpf() syscall where not required
  • Remove CAP_BPF from workload capability sets using Kubernetes securityContext or systemd unit directives
bash
# Configuration example
# Disable unprivileged BPF program loading
sysctl -w kernel.unprivileged_bpf_disabled=1
echo 'kernel.unprivileged_bpf_disabled=1' >> /etc/sysctl.d/99-bpf-hardening.conf

# Verify setting
sysctl kernel.unprivileged_bpf_disabled

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.