Untrusted Pointer Dereference in Linux kernel - CVE-2026-98037
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a NULL or stale-memory dereference.
The vulnerability exists due to improper validation of untrusted pointer state in the BPF verifier's type_is_ptr_alloc_obj() predicate when validating a refcount-only local kptr after RCU protection ends. A local user can pass a demoted local kptr to bpf_refcount_acquire() to trigger a NULL or stale-memory dereference.
Fault-protected reads of the demoted pointer remain valid.