NULL pointer dereference in Linux kernel - CVE-2026-98043
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to incorrect non-NULL pointer inference in the BPF verifier's reg_not_null() function when processing BPF programs with pointer arithmetic using unbounded offsets. A local user can load a crafted BPF program to cause a denial of service.