NULL pointer dereference in Linux kernel - CVE-2026-98134
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper null pointer validation in check_cond_jmp_op() in the BPF verifier when comparing pointer registers in a BPF program. A local user can submit a crafted BPF program that causes an unchecked null pointer dereference to cause a denial of service.