Bug 2541291 (CVE-2026-98062) - CVE-2026-98062 kernel: bpf: Mark signal tracepoint siginfo arguments as scalar
Summary: CVE-2026-98062 kernel: bpf: Mark signal tracepoint siginfo arguments as scalar
Keywords:
Status: NEW
Alias: CVE-2026-98062
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:15 UTC by OSIDB Bzimport
Modified: 2026-09-29 00:20 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:15:30 UTC
In the Linux kernel, the following vulnerability has been resolved:

bpf: Mark signal tracepoint siginfo arguments as scalar

The signal_generate and signal_deliver tracepoints declare their info
argument as a struct kernel_siginfo pointer. btf_ctx_access() therefore
treats it as a trusted pointer for tp_btf programs.

Signal delivery also uses SEND_SIG_NOINFO and SEND_SIG_PRIV as special
values for this argument. Those values are zero and one respectively,
and are not pointers. A tp_btf program can currently dereference either
value and fault the kernel. In particular, signal_generate can run from
timer interrupt context, turning the fault into a kernel panic.

Record both tracepoints in raw_tp_null_args[] and mark argument one as
a non-pointer. This preserves scalar access to the cookie while rejecting
direct and helper-mediated pointer use. Merely marking it nullable would
not suffice because SEND_SIG_PRIV is nonzero.


Note You need to log in before you can comment on or make changes to this bug.