---
id: CVE-2026-98064
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Fix NULL-ptr-deref when showing a void BTF type

  btf_modifier_show() resolves the modifier and then calls
  btf_type_ops(t)->show() unconditionally
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Fix NULL-ptr-deref when showing a void BTF type

  btf_modifier_show() resolves the modifier and then calls
  btf_type_ops(t)->show() unconditionally. For the void typ…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= c4d0bfb45068d853a478b9067a95969b1886a30f <
    717abdfd1d559d01fdd102023f0a990fb0437240
  - >-
    Linux >= c4d0bfb45068d853a478b9067a95969b1886a30f <
    98f1cb95221332139acf514350ae2cae3b8656c5
  - >-
    Linux >= c4d0bfb45068d853a478b9067a95969b1886a30f <
    5324f4e75ff6e9c2ca2e267c5f34f0937f9d0ac9
  - >-
    Linux >= c4d0bfb45068d853a478b9067a95969b1886a30f <
    4ea508b9ebd78bce7f212166d2e2cba66b875f08
  - Linux 5.10
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:35.437'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98064'
references:
  - url: 'https://git.kernel.org/stable/c/4ea508b9ebd78bce7f212166d2e2cba66b875f08'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5324f4e75ff6e9c2ca2e267c5f34f0937f9d0ac9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/717abdfd1d559d01fdd102023f0a990fb0437240'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/98f1cb95221332139acf514350ae2cae3b8656c5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.841Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix NULL-ptr-deref when showing a void BTF type

btf_modifier_show() resolves the modifier and then calls
btf_type_ops(t)->show() unconditionally. For the void type (type_id 0,
BTF_KIND_UNKN) kind_ops[] has no entry, so ->show is NULL.

A "const void" (a modifier resolving to void) cannot be a map key or
value - map_check_btf() rejects it because void has no size - so the map
dump path does not reach it. But bpf_snprintf_btf() takes a type_id
straight from the BPF program, and passing such a "const void" from the
vmlinux BTF NULL-derefs:

KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f]
RIP: 0010:btf_modifier_show (kernel/bpf/btf.c:2914)
Call Trace:
 <TASK>
 btf_type_show (kernel/bpf/btf.c:8251)
 btf_type_snprintf_show (kernel/bpf/btf.c:8321)
 bpf_snprintf_btf (kernel/trace/bpf_trace.c:1047)
 bpf_prog_test_run_raw_tp (net/bpf/test_run.c:829)
 __sys_bpf (kernel/bpf/syscall.c:4804)
 do_syscall_64 (arch/x86/entry/syscall_64.c:94)
 entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
 </TASK>

Fall back to btf_df_show() when the resolved type has no show op; it
emits the "<unsupported kind:N>" placeholder already used for kinds like
FWD and FUNC. bpf_snprintf_btf() then returns the length as usual.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
