Improper locking in Linux kernel - CVE-2026-98045
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in the faultable bpf_get_stack() and bpf_get_task_stack() helper prototypes when resolving user-space build IDs from a non-sleepable context. A local user can invoke a faultable stack helper from a non-sleepable kernel context to cause a denial of service.
The task-stack helper can be invoked from a non-sleepable timer callback in a sleepable program.