{"id":"CVE-2026-98062","published":"2026-09-25T11:17:35.220","lastModified":"2026-09-25T11:17:35.220","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mark signal tracepoint siginfo arguments as scalar\n\nThe signal_generate and signal_deliver tracepoints declare their info\nargument as a struct kernel_siginfo pointer. btf_ctx_access() therefore\ntreats it as a trusted pointer for tp_btf programs.\n\nSignal delivery also uses SEND_SIG_NOINFO and SEND_SIG_PRIV as special\nvalues for this argument. Those values are zero and one respectively,\nand are not pointers. A tp_btf program can currently dereference either\nvalue and fault the kernel. In particular, signal_generate can run from\ntimer interrupt context, turning the fault into a kernel panic.\n\nRecord both tracepoints in raw_tp_null_args[] and mark argument one as\na non-pointer. This preserves scalar access to the cookie while rejecting\ndirect and helper-mediated pointer use. Merely marking it nullable would\nnot suffice because SEND_SIG_PRIV is nonzero.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/0e78cb242a57e481061fcb542fed4d51afba25c4","tags":[]},{"url":"https://git.kernel.org/stable/c/77515ab12e4983e6416f8c35039a3f0c0822ac70","tags":[]},{"url":"https://git.kernel.org/stable/c/d2eaea3599bcce659ce91862254dc91bcbdb6351","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}