« Volver al listado

CVE-2026-98065

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject key-less BTF for hash maps

map_check_btf() allows a key-less BTF (btf_key_type_id == 0) only for maps that have a ->map_check_btf callback, and leaves the actual decision to that callback. Hash maps used to have no ->map_check_btf, so a key-less BTF was rejected outright.

That changed when htab and rhtab gained a ->map_check_btf to register a dtor - htab in commit 1df97a7453ee ("bpf: Register dtor for freeing special fields") and rhtab in commit 6905f8601298 ("bpf: Allow special fields in resizable hashtab").

Leer descripción completaMostrar menos

Neither looks at the key, so a key-less hash map now passes map_check_btf() and gets created. Reading it back through bpffs feeds the key type_id 0 into btf_type_seq_show(); btf_type_by_id() returns the void type, kind_ops[BTF_KIND_UNKN] is NULL, and btf_type_show() dereferences it:

Reject a key-less BTF in htab_map_check_btf() and rhtab_map_check_btf(), restoring the previous behavior.

Detalles técnicos trazas, registros y código del informe original
RIP: 0010:btf_type_show+0x223/0x2e0 kernel/bpf/btf.c:8232
RSP: 0018:ffffc9000399f868 EFLAGS: 00010206
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000005 RSI: 0000000000000000 RDI: 0000000000000028
RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
R10: ffffc9000399f970 R11: 0000000000000001 R12: ffffffff9b96b140
R13: ffffc9000399f8e0 R14: ffff88803d393c00 R15: 0000000000000003
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000000000 CR3: 000000003d213000 CR4: 0000000000352ef0
DR0: 0000000039ae8f55 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 btf_type_seq_show_flags+0xca/0x120 kernel/bpf/btf.c:8250
 htab_map_seq_show_elem+0x12e/0x350 kernel/bpf/hashtab.c:1669
 map_seq_show+0x13d/0x1e0 kernel/bpf/inode.c:293
 traverse.part.0.constprop.0+0x107/0x650 fs/seq_file.c:112
 traverse fs/seq_file.c:99 [inline]
 seq_read_iter+0x93f/0x1270 fs/seq_file.c:196
 seq_read+0x344/0x4d0 fs/seq_file.c:163
 vfs_read+0x1e4/0xb40 fs/read_write.c:572
 ksys_pread64 fs/read_write.c:764 [inline]
 __do_sys_pread64 fs/read_write.c:772 [inline]
 __se_sys_pread64 fs/read_write.c:769 [inline]
 __x64_sys_pread64+0x1eb/0x250 fs/read_write.c:769
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x123/0x790 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98065",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "451a84a3ad3c897c03181af433e7c98640730f1f",
              "lessThan": "54098e3fe34ec190bc256b338b9a93c7e2dc9354",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "51a17f0ce19c4ee2a25cf16c93490d509b1ebb0a",
              "lessThan": "fa047f2a025003f5654ebd76539f16a6ead0401a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1df97a7453eec80c1912c2d0360290a3970a7671",
              "lessThan": "7ca231252820c47aaec42a5db580db98f9b64724",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1df97a7453eec80c1912c2d0360290a3970a7671",
              "lessThan": "0895a0c0734703be5532f3883c42db95615fd98b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/hashtab.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/hashtab.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:35.553",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0895a0c0734703be5532f3883c42db95615fd98b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/54098e3fe34ec190bc256b338b9a93c7e2dc9354",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7ca231252820c47aaec42a5db580db98f9b64724",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fa047f2a025003f5654ebd76539f16a6ead0401a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject key-less BTF for hash maps\n\nmap_check_btf() allows a key-less BTF (btf_key_type_id == 0) only for\nmaps that have a ->map_check_btf callback, and leaves the actual\ndecision to that callback. Hash maps used to have no ->map_check_btf,\nso a key-less BTF was rejected outright.\n\nThat changed when htab and rhtab gained a ->map_check_btf to register a\ndtor - htab in commit 1df97a7453ee (\"bpf: Register dtor for freeing\nspecial fields\") and rhtab in commit 6905f8601298 (\"bpf: Allow special\nfields in resizable hashtab\"). Neither looks at the key, so a key-less\nhash map now passes map_check_btf() and gets created. Reading it back\nthrough bpffs feeds the key type_id 0 into btf_type_seq_show();\nbtf_type_by_id() returns the void type, kind_ops[BTF_KIND_UNKN] is NULL,\nand btf_type_show() dereferences it:\n\nRIP: 0010:btf_type_show+0x223/0x2e0 kernel/bpf/btf.c:8232\nRSP: 0018:ffffc9000399f868 EFLAGS: 00010206\nRAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\nRDX: 0000000000000005 RSI: 0000000000000000 RDI: 0000000000000028\nRBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000\nR10: ffffc9000399f970 R11: 0000000000000001 R12: ffffffff9b96b140\nR13: ffffc9000399f8e0 R14: ffff88803d393c00 R15: 0000000000000003\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000200000000000 CR3: 000000003d213000 CR4: 0000000000352ef0\nDR0: 0000000039ae8f55 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400\nCall Trace:\n <TASK>\n btf_type_seq_show_flags+0xca/0x120 kernel/bpf/btf.c:8250\n htab_map_seq_show_elem+0x12e/0x350 kernel/bpf/hashtab.c:1669\n map_seq_show+0x13d/0x1e0 kernel/bpf/inode.c:293\n traverse.part.0.constprop.0+0x107/0x650 fs/seq_file.c:112\n traverse fs/seq_file.c:99 [inline]\n seq_read_iter+0x93f/0x1270 fs/seq_file.c:196\n seq_read+0x344/0x4d0 fs/seq_file.c:163\n vfs_read+0x1e4/0xb40 fs/read_write.c:572\n ksys_pread64 fs/read_write.c:764 [inline]\n __do_sys_pread64 fs/read_write.c:772 [inline]\n __se_sys_pread64 fs/read_write.c:769 [inline]\n __x64_sys_pread64+0x1eb/0x250 fs/read_write.c:769\n do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]\n do_syscall_64+0x123/0x790 arch/x86/entry/syscall_64.c:84\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nReject a key-less BTF in htab_map_check_btf() and rhtab_map_check_btf(),\nrestoring the previous behavior."
    }
  ],
  "lastModified": "2026-10-03T11:18:27.217",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}