-

CVE-2026-98064

bpf: Fix NULL-ptr-deref when showing a void BTF type

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix NULL-ptr-deref when showing a void BTF type

btf_modifier_show() resolves the modifier and then calls
btf_type_ops(t)->show() unconditionally. For the void type (type_id 0,
BTF_KIND_UNKN) kind_ops[] has no entry, so ->show is NULL.

A "const void" (a modifier resolving to void) cannot be a map key or
value - map_check_btf() rejects it because void has no size - so the map
dump path does not reach it. But bpf_snprintf_btf() takes a type_id
straight from the BPF program, and passing such a "const void" from the
vmlinux BTF NULL-derefs:

KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]
RIP: 0010:btf_modifier_show (kernel/bpf/btf.c:2914)
Call Trace:
 <TASK>
 btf_type_show (kernel/bpf/btf.c:8251)
 btf_type_snprintf_show (kernel/bpf/btf.c:8321)
 bpf_snprintf_btf (kernel/trace/bpf_trace.c:1047)
 bpf_prog_test_run_raw_tp (net/bpf/test_run.c:829)
 __sys_bpf (kernel/bpf/syscall.c:4804)
 do_syscall_64 (arch/x86/entry/syscall_64.c:94)
 entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
 </TASK>

Fall back to btf_df_show() when the resolved type has no show op; it
emits the "<unsupported kind:N>" placeholder already used for kinds like
FWD and FUNC. bpf_snprintf_btf() then returns the length as usual.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version c4d0bfb45068d853a478b9067a95969b1886a30f
Version < cf528f2d7a0a54f2a3c6d439cfa3c8d7dfe90d8d
Status affected
Version c4d0bfb45068d853a478b9067a95969b1886a30f
Version < adb15557a641cb8a31f83e5f62bd12042b138c7b
Status affected
Version c4d0bfb45068d853a478b9067a95969b1886a30f
Version < 62b00074b58ccf43f61f70f2cfcac80937b530c6
Status affected
Version c4d0bfb45068d853a478b9067a95969b1886a30f
Version < 86d86f9fcf62dd3654090fbf3cf7ae5f42aa0706
Status affected
Version c4d0bfb45068d853a478b9067a95969b1886a30f
Version < 717abdfd1d559d01fdd102023f0a990fb0437240
Status affected
Version c4d0bfb45068d853a478b9067a95969b1886a30f
Version < 98f1cb95221332139acf514350ae2cae3b8656c5
Status affected
Version c4d0bfb45068d853a478b9067a95969b1886a30f
Version < 5324f4e75ff6e9c2ca2e267c5f34f0937f9d0ac9
Status affected
Version c4d0bfb45068d853a478b9067a95969b1886a30f
Version < 4ea508b9ebd78bce7f212166d2e2cba66b875f08
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/717abdfd1d559d01fdd102023f0a990fb0437240
https://git.kernel.org/stable/c/98f1cb95221332139acf514350ae2cae3b8656c5
https://git.kernel.org/stable/c/5324f4e75ff6e9c2ca2e267c5f34f0937f9d0ac9
https://git.kernel.org/stable/c/4ea508b9ebd78bce7f212166d2e2cba66b875f08
https://git.kernel.org/stable/c/62b00074b58ccf43f61f70f2cfcac80937b530c6
https://git.kernel.org/stable/c/86d86f9fcf62dd3654090fbf3cf7ae5f42aa0706
https://git.kernel.org/stable/c/adb15557a641cb8a31f83e5f62bd12042b138c7b
https://git.kernel.org/stable/c/cf528f2d7a0a54f2a3c6d439cfa3c8d7dfe90d8d