CVE-2026-98062: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: bpf: Mark signal tracepoint siginfo arguments as scalar The signal_generate and signal_deliver tracepoints declare their info argument as a struct kernel_siginfo pointer. btf_ctx_access() therefore treats it as a trusted pointer for tp_btf programs. Signal delivery also uses SEND_SIG_NOINFO and SEND_SIG_PRIV as special values for this argument. Those values are zero and one respectively, and are not pointers. A tp_btf program can currently dereference either value and fault the kernel. In particular, signal_generate can run from timer interrupt context, turning the fault into a kernel panic. Record both tracepoints in raw_tp_null_args[] and mark argument one as a non-pointer. This preserves scalar access to the cookie while rejecting direct and helper-mediated pointer use. Merely marking it nullable would not suffice because SEND_SIG_PRIV is nonzero.
Affected products
- Linux Linux Kernel: from 6.12.6, before 6.13 (fixed in 6.13); from 6.13.1, before 6.18.53 (fixed in 6.18.53); from 6.19, before 7.2.7 (fixed in 7.2.7); version 6.13 only; version 7.3 only
Published 2026-09-25. Last modified 2026-10-02.