5.5

CVE-2026-98062

bpf: Mark signal tracepoint siginfo arguments as scalar

In the Linux kernel, the following vulnerability has been resolved:

bpf: Mark signal tracepoint siginfo arguments as scalar

The signal_generate and signal_deliver tracepoints declare their info
argument as a struct kernel_siginfo pointer. btf_ctx_access() therefore
treats it as a trusted pointer for tp_btf programs.

Signal delivery also uses SEND_SIG_NOINFO and SEND_SIG_PRIV as special
values for this argument. Those values are zero and one respectively,
and are not pointers. A tp_btf program can currently dereference either
value and fault the kernel. In particular, signal_generate can run from
timer interrupt context, turning the fault into a kernel panic.

Record both tracepoints in raw_tp_null_args[] and mark argument one as
a non-pointer. This preserves scalar access to the cookie while rejecting
direct and helper-mediated pointer use. Merely marking it nullable would
not suffice because SEND_SIG_PRIV is nonzero.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.12.6 < 6.13
Linux ≫ Linux Kernel Version >= 6.13.1 < 6.18.53
Linux ≫ Linux Kernel Version >= 6.19 < 7.2.7
Linux ≫ Linux Kernel Version 6.13 Update -
Linux ≫ Linux Kernel Version 6.13 Update rc3
Linux ≫ Linux Kernel Version 6.13 Update rc4
Linux ≫ Linux Kernel Version 6.13 Update rc5
Linux ≫ Linux Kernel Version 6.13 Update rc6
Linux ≫ Linux Kernel Version 6.13 Update rc7
Linux ≫ Linux Kernel Version 7.3 Update rc1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/0e78cb242a57e481061fcb542fed4d51afba25c4
Patch
https://git.kernel.org/stable/c/d2eaea3599bcce659ce91862254dc91bcbdb6351
Patch
https://git.kernel.org/stable/c/77515ab12e4983e6416f8c35039a3f0c0822ac70
Patch