CVE-2026-98065 Overview
CVE-2026-98065 is a Linux kernel vulnerability in the Berkeley Packet Filter (BPF) subsystem. The flaw allows creation of hash maps with a key-less BPF Type Format (BTF) descriptor. Reading such a map through the BPF filesystem (bpffs) triggers a null pointer dereference in btf_type_show(), crashing the kernel.
The regression was introduced when htab and rhtab gained a ->map_check_btf callback to register destructors for special fields. Neither callback inspected the key type, so key-less BTF slipped past validation that previously rejected it outright.
Critical Impact
Local unprivileged users with BPF access can trigger a kernel null pointer dereference and denial of service by creating a hash map with key-less BTF and reading it via bpffs.
Affected Products
- Linux kernel versions containing commit 1df97a7453ee ("bpf: Register dtor for freeing special fields")
- Linux kernel versions containing commit 6905f8601298 ("bpf: Allow special fields in resizable hashtab")
- Linux kernel BPF subsystem (kernel/bpf/hashtab.c, kernel/bpf/btf.c)
Discovery Timeline
- 2026-09-25 - CVE-2026-98065 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98065
Vulnerability Analysis
The map_check_btf() function in the Linux kernel BPF subsystem permits a key-less BTF (btf_key_type_id == 0) only when a map provides a ->map_check_btf callback. The validation decision is then delegated to that callback. Historically, hash maps did not implement ->map_check_btf, so the generic check rejected key-less BTF.
Two commits changed that behavior. Commit 1df97a7453ee added ->map_check_btf to htab to register a destructor for freeing special fields. Commit 6905f8601298 did the same for rhtab. Neither callback inspects the key type, so key-less hash maps now pass validation and are successfully created.
When userspace reads such a map through bpffs, the kernel invokes btf_type_seq_show() with type_id zero. btf_type_by_id() returns the void type, and kind_ops[BTF_KIND_UNKN] is NULL. The subsequent dereference in btf_type_show() at kernel/bpf/btf.c:8232 crashes the kernel.
Root Cause
The root cause is incomplete input validation in the hash map BTF check callbacks. Adding ->map_check_btf without preserving the key-presence requirement removed an implicit safety check that the generic map_check_btf() path previously enforced for hash maps.
Attack Vector
An attacker with the ability to create BPF maps (typically requiring CAP_BPF or equivalent, though unprivileged BPF may be enabled on some systems) can create a hash map with a BTF value definition but no key type. Reading the map through /sys/fs/bpf/ triggers the sequence that reaches btf_type_show() with a null operations pointer, causing a kernel crash and denial of service.
The vulnerability is described in prose; no proof-of-concept code is published alongside the fix. Technical details are available in the upstream commits linked in the references.
Detection Methods for CVE-2026-98065
Indicators of Compromise
- Kernel oops or panic messages referencing btf_type_show+0x223/0x2e0 in kernel/bpf/btf.c
- Call traces containing htab_map_seq_show_elem followed by map_seq_show and btf_type_seq_show_flags
- Unexpected process termination for seq_read or pread64 syscalls accessing paths under /sys/fs/bpf/
Detection Strategies
- Monitor dmesg and journald for null pointer dereference traces originating in the BPF BTF code path
- Alert on BPF map creation syscalls (bpf(BPF_MAP_CREATE)) for BPF_MAP_TYPE_HASH or BPF_MAP_TYPE_HASH_OF_MAPS where btf_key_type_id is zero
- Audit processes with CAP_BPF or CAP_SYS_ADMIN that create maps and then open file descriptors under bpffs
Monitoring Recommendations
- Enable kernel crash dump collection (kdump) to capture faulting state for post-incident analysis
- Forward kernel logs to a central SIEM and correlate oops events with recent BPF syscall activity
- Track running kernel versions against the upstream fix commits 0895a0c0734703be5532f3883c42db95615fd98b and 7ca231252820c47aaec42a5db580db98f9b64724
How to Mitigate CVE-2026-98065
Immediate Actions Required
- Apply the upstream Linux kernel patches that add key-less BTF rejection in htab_map_check_btf() and rhtab_map_check_btf()
- Restrict BPF syscall access to trusted users by setting kernel.unprivileged_bpf_disabled=1 where feasible
- Audit which workloads require CAP_BPF and remove the capability from containers and services that do not need it
Patch Information
The fix restores the previous behavior by explicitly rejecting a key-less BTF inside the hash map and resizable hash table check callbacks. The relevant upstream commits are available at the Linux Kernel Commit 0895a0c0 and Linux Kernel Commit 7ca23125. Rebuild and deploy a kernel that includes both commits, or install vendor-provided stable kernel updates that backport the fix.
Workarounds
- Disable unprivileged BPF access by writing 1 to /proc/sys/kernel/unprivileged_bpf_disabled to limit map creation to privileged processes
- Use seccomp or Linux Security Module policies to block the bpf() syscall for workloads that do not require it
- Avoid mounting bpffs or restrict permissions on /sys/fs/bpf/ to reduce the attack surface for triggering the show path
# Disable unprivileged BPF at runtime
sysctl -w kernel.unprivileged_bpf_disabled=1
# Persist across reboots
echo 'kernel.unprivileged_bpf_disabled=1' > /etc/sysctl.d/90-bpf-hardening.conf
# Restrict bpffs access
chmod 700 /sys/fs/bpf
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.