NULL pointer dereference in Linux kernel - CVE-2026-98038
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger a null pointer dereference.
The vulnerability exists due to improper reference ownership tracking in the BPF verifier when verifying BPF programs that acquire references from borrowed RCU kptrs. A local user can load a crafted BPF program that uses a borrowed RCU kptr without a required NULL check to trigger a null pointer dereference.
The issue occurs when the refcounted object does not contain a graph node and its last real reference is dropped during an RCU critical section.