{"id":"CVE-2026-98043","published":"2026-09-25T11:17:33.090","lastModified":"2026-09-25T11:17:33.090","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Don't infer non-NULL from a pointer with an unbounded offset\n\nreg_not_null() decides that a register holds a non-NULL value by\nlooking at its type alone. For pointer types that allow arithmetic the\ntype only guarantees a non-NULL base, in case of an unbound offset\nthe runtime offset value might still add up to NULL.\nConsider the followng program:\n\n  r6 = bpf_map_lookup_elem(map, &0);  /* present */\n  if (r6 == 0) return 0;\n  r7 = bpf_map_lookup_elem(map, &1);  /* absent, NULL at runtime */\n  r8 = r7;\n  r8 -= r6;     /* pointer - pointer: unknown scalar, -r6 */\n  r8 <<= 1;\n  r8 >>= 1;     /* any non-negative offset is accepted by */\n                /* check_reg_sane_offset_ptr() */\n  r6 += r8;     /* verifier: map value;    runtime: zero  */\n  if (r7 != r6) return 0;\n  *(u8 *)(r7 + 0);  /* r7 is inferred non-NULL, both are zero */\n\nAt runtime both registers are zero, the comparison is true and the\nload faults with NULL pointer dereference.\n\nRequire the offset to be within +-BPF_MAX_VAR_OFF in reg_not_null().","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/67b529f521a6676cdfc78b91b0217d7eaa84216b","tags":[]},{"url":"https://git.kernel.org/stable/c/cb6642048739bf4ee5aa09fe465511f1e87caa63","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}