← All Advisories

CVE-2026-98064

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98064

Key Details

CVECVE-2026-98064
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix NULL-ptr-deref when showing a void BTF type

btf_modifier_show() resolves the modifier and then calls

btf_type_ops(t)->show() unconditionally. For the void type (type_id 0,

BTF_KIND_UNKN) kind_ops[] has no entry, so ->show is NULL.

A "const void" (a modifier resolving to void) cannot be a map key or

value - map_check_btf() rejects it because void has no size - so the map

dump path does not reach it. But bpf_snprintf_btf() takes a type_id

straight from the BPF program, and passing such a "const void" from the

vmlinux BTF NULL-derefs:

KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]

RIP: 0010:btf_modifier_show (kernel/bpf/btf.c:2914)

Call Trace:

<TASK>

btf_type_show (kernel/bpf/btf.c:8251)

btf_type_snprintf_show (kernel/bpf/btf.c:8321)

bpf_snprintf_btf (kernel/trace/bpf_trace.c:1047)

bpf_prog_test_run_raw_tp (net/bpf/test_run.c:829)

__sys_bpf (kernel/bpf/syscall.c:4804)

do_syscall_64 (arch/x86/entry/syscall_64.c:94)

entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)

</TASK>

Fall back to btf_df_show() when the resolved type has no show op; it

emits the "<unsupported kind:N>" placeholder already used for kinds like

FWD and FUNC. bpf_snprintf_btf() then returns the length as usual. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98064
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98064