NULL pointer dereference in Linux kernel - CVE-2026-98059
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper null pointer handling in the BPF verifier handling of the sched_process_wait tracepoint argument when executing a JITed BPF program that dereferences the argument without a NULL check. A local user can execute a JITed BPF program with an unchecked dereference and trigger a wait for any child to cause a denial of service.
The tracepoint argument can be NULL for wait4(-1) and waitid(P_ALL).