CVE-2026-98046
In the Linux kernel, the following vulnerability has been resolved:
bpf: Mark bpf_btf_find_by_name_kind() as sleepable
When bpf_btf_find_by_name_kind() finds a type in module BTF, it returns a new BTF object fd through __btf_new_fd(). This reaches anon_inode_getfd(), which can sleep while allocating or expanding the current task fd table.
The helper prototype does not set might_sleep, so the verifier allows the helper in non-sleepable contexts such as BPF timer callbacks. The fd allocation can then sleep in softirq context and install the fd into the interrupted task.
Mark the helper as sleepable. This preserves calls from the main body of a sleepable syscall program while rejecting calls from its non-sleepable regions.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/17f54a8f2b9714529d56edbbe12d448ccdbbf469
- https://git.kernel.org/stable/c/29e40175617216fbd4544529f6bfb51d1ab95ba1
- https://git.kernel.org/stable/c/4d8784226bd3c6a707975081f986078f40456cec
- https://git.kernel.org/stable/c/620614bf7672130c43b3cff375525a2202f61979
- https://git.kernel.org/stable/c/7bf23cf7c9c0e0b5e638e497cdc0ec3f223742cc
- https://git.kernel.org/stable/c/b843ab43ac9d2fa1ddd0dab8d0dcc19dbf764e2f
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98046",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3d78417b60fba249cc555468cb72d96f5cde2964",
"lessThan": "7bf23cf7c9c0e0b5e638e497cdc0ec3f223742cc",
"versionType": "git"
},
{
"status": "affected",
"version": "3d78417b60fba249cc555468cb72d96f5cde2964",
"lessThan": "b843ab43ac9d2fa1ddd0dab8d0dcc19dbf764e2f",
"versionType": "git"
},
{
"status": "affected",
"version": "3d78417b60fba249cc555468cb72d96f5cde2964",
"lessThan": "29e40175617216fbd4544529f6bfb51d1ab95ba1",
"versionType": "git"
},
{
"status": "affected",
"version": "3d78417b60fba249cc555468cb72d96f5cde2964",
"lessThan": "4d8784226bd3c6a707975081f986078f40456cec",
"versionType": "git"
},
{
"status": "affected",
"version": "3d78417b60fba249cc555468cb72d96f5cde2964",
"lessThan": "17f54a8f2b9714529d56edbbe12d448ccdbbf469",
"versionType": "git"
},
{
"status": "affected",
"version": "3d78417b60fba249cc555468cb72d96f5cde2964",
"lessThan": "620614bf7672130c43b3cff375525a2202f61979",
"versionType": "git"
}
],
"programFiles": [
"kernel/bpf/btf.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"kernel/bpf/btf.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:33.440",
"references": [
{
"url": "https://git.kernel.org/stable/c/17f54a8f2b9714529d56edbbe12d448ccdbbf469",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/29e40175617216fbd4544529f6bfb51d1ab95ba1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4d8784226bd3c6a707975081f986078f40456cec",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/620614bf7672130c43b3cff375525a2202f61979",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7bf23cf7c9c0e0b5e638e497cdc0ec3f223742cc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b843ab43ac9d2fa1ddd0dab8d0dcc19dbf764e2f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mark bpf_btf_find_by_name_kind() as sleepable\n\nWhen bpf_btf_find_by_name_kind() finds a type in module BTF, it\nreturns a new BTF object fd through __btf_new_fd(). This reaches\nanon_inode_getfd(), which can sleep while allocating or expanding the\ncurrent task fd table.\n\nThe helper prototype does not set might_sleep, so the verifier allows\nthe helper in non-sleepable contexts such as BPF timer callbacks. The\nfd allocation can then sleep in softirq context and install the fd into\nthe interrupted task.\n\nMark the helper as sleepable. This preserves calls from the main body\nof a sleepable syscall program while rejecting calls from its\nnon-sleepable regions."
}
],
"lastModified": "2026-10-03T11:18:26.187",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}