Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-98046
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to install a file descriptor into an interrupted task.
The vulnerability exists due to improper execution-context validation in the bpf_btf_find_by_name_kind() helper prototype when invoking the helper from a non-sleepable BPF timer callback. A local user can invoke the helper from a BPF timer callback to install a file descriptor into an interrupted task.