Bug 2541185 (CVE-2026-98046) - CVE-2026-98046 kernel: bpf: Mark bpf_btf_find_by_name_kind() as sleepable
Summary: CVE-2026-98046 kernel: bpf: Mark bpf_btf_find_by_name_kind() as sleepable
Keywords:
Status: NEW
Alias: CVE-2026-98046
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 10:55 UTC by OSIDB Bzimport
Modified: 2026-09-28 23:18 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 10:55:55 UTC
In the Linux kernel, the following vulnerability has been resolved:

bpf: Mark bpf_btf_find_by_name_kind() as sleepable

When bpf_btf_find_by_name_kind() finds a type in module BTF, it
returns a new BTF object fd through __btf_new_fd(). This reaches
anon_inode_getfd(), which can sleep while allocating or expanding the
current task fd table.

The helper prototype does not set might_sleep, so the verifier allows
the helper in non-sleepable contexts such as BPF timer callbacks. The
fd allocation can then sleep in softirq context and install the fd into
the interrupted task.

Mark the helper as sleepable. This preserves calls from the main body
of a sleepable syscall program while rejecting calls from its
non-sleepable regions.


Note You need to log in before you can comment on or make changes to this bug.