---
id: CVE-2026-98045
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Mark faultable stack helpers as sleepable

  The faultable variants of bpf_get_stack() and bpf_get_task_stack() pass
  may_fault=true into the common stack collection …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Mark faultable stack helpers as sleepable

  The faultable variants of bpf_get_stack() and bpf_get_task_stack() pass
  may_fault=true into the common stack collection …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= d4dd9775ec242425576af93daadb80a34083a53c <
    44b8d370f2725bad215da3e67668e98ba96671bd
  - >-
    Linux >= d4dd9775ec242425576af93daadb80a34083a53c <
    3014e8a8bdad55075d89836ad9c10710a9a69837
  - >-
    Linux >= d4dd9775ec242425576af93daadb80a34083a53c <
    19e8d5a98afd071d8c1c5adeccf92b3c42eddc70
  - >-
    Linux >= d4dd9775ec242425576af93daadb80a34083a53c <
    9d02927fdf4e930893c92e35fed01a2704496900
  - Linux 6.12
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:33.330'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98045'
references:
  - url: 'https://git.kernel.org/stable/c/19e8d5a98afd071d8c1c5adeccf92b3c42eddc70'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3014e8a8bdad55075d89836ad9c10710a9a69837'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/44b8d370f2725bad215da3e67668e98ba96671bd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9d02927fdf4e930893c92e35fed01a2704496900'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.848Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: Mark faultable stack helpers as sleepable

The faultable variants of bpf_get_stack() and bpf_get_task_stack() pass
may_fault=true into the common stack collection code. Resolving user-space
build IDs may then call build_id_parse_file() and block on filesystem
reads.

Neither helper prototype sets might_sleep. Since prototype selection uses
the sleepability of the whole program, the verifier can still allow these
helpers from a non-sleepable region within that program, such as an
explicit RCU or preemption-disabled region. The task-stack helper can also
be called from a non-sleepable timer callback of a sleepable program.

Mark both faultable prototypes as sleepable. The existing helper context
check then rejects these calls while continuing to allow them in genuinely
sleepable contexts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
