Type Confusion in Linux kernel - CVE-2026-98062
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper type handling in the signal_generate and signal_deliver tracepoints when tp_btf programs access the siginfo argument. A local user can trigger signal tracepoint processing with a tp_btf program that dereferences the argument to cause a denial of service.
The signal_generate tracepoint can execute in timer interrupt context.