{"api_version":"1","generated_at":"2026-10-01T07:59:22+00:00","cve":"CVE-2026-98134","urls":{"html":"https://cve.report/CVE-2026-98134","api":"https://cve.report/api/cve/CVE-2026-98134.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-98134","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-98134"},"summary":{"title":"bpf: check_cond_jmp_op(): properly infer if register is null","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: check_cond_jmp_op(): properly infer if register is null\n\nNicholas Carlini reported a bug when verifier can incorrectly infer\nthat a pointer is non-null. The bug occurs when two pointers are\ncompared and one of them has a type w/o PTR_MAYBE_NULL flag,\nbut which allows a value to be NULL at runtime.\nHere is an example:\n\n  // `a` is PTR_TO_MEM | MEM_RDONLY | PTR_UNTRUSTED\n  // `a` is 0 at runtime.\n  // `b` is PTR_TO_MAP_VALUE | PTR_MAYBE_NULL\n  void *a = bpf_rdonly_cast(0, 0);\n  int  *b = bpf_map_lookup_elem(...);\n\n  if (a == b)\n    *b = 42;  // verifier does not catch null pointer dereference\n\nThis happens because of a special case in check_cond_jmp_op(),\nwhich attempts to strip PTR_MAYBE_NULL flags from pointer types,\nwhen processing comparisons like `rA == rB`, if either rA or rB can't\nbe null.\n\nThe non-null property is derived based on the absence of\nPTR_MAYBE_NULL flag on rA's or rB's type. But that is not sufficient\nfor types like PTR_TO_MEM, as in the example.\n\nThis patch replaces type_may_be_null() call with reg_not_null(),\nwhich contains an allowlist of types for which absence of\nPTR_MAYBE_NULL actually means that the value can't be NULL at runtime.\n\nAt the moment, the list in the reg_not_null() omits two types for\nwhich PTR_MAYBE_NULL is applicable: PTR_TO_XDP_SOCK and PTR_TO_BUF.\nIn order to remain backward compatible, and assuming that only\ncomparison between pointers of the same type makes sense,\nthis commit extends reg_not_null(). W/o such an extension e.g.\nverifier_jeq_infer_not_null/null_ptr_to_map_value fails.\n\nreg_not_null() can be extended further, but I deem that out of scope\nfor the fix at hand. Explicit base_type(...) != PTR_TO_BTF_ID\nchecks in the check_cond_jmp_op() can be removed with migration to\nreg_not_null(), but that is a behavioural change, as the special case\nwould start matching for PTR_TO_BTF_ID that is also is_trusted_reg().\nI omit the behavioural change from this commit.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:44","updated_at":"2026-09-30 14:10:59"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/d3ef6c097ba078e1f8c7239d76a0ce8b61e75095","name":"https://git.kernel.org/stable/c/d3ef6c097ba078e1f8c7239d76a0ce8b61e75095","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b55c9f019e169ed0d01394f96e172286a8b21b99","name":"https://git.kernel.org/stable/c/b55c9f019e169ed0d01394f96e172286a8b21b99","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98134","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98134","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected befae75856ab406a3f3fab2aa2118cf3b2dfe3e6 b55c9f019e169ed0d01394f96e172286a8b21b99 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected befae75856ab406a3f3fab2aa2118cf3b2dfe3e6 d3ef6c097ba078e1f8c7239d76a0ce8b61e75095 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"98134","cve":"CVE-2026-98134","epss":"0.001560000","percentile":"0.040350000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"b55c9f019e169ed0d01394f96e172286a8b21b99","status":"affected","version":"befae75856ab406a3f3fab2aa2118cf3b2dfe3e6","versionType":"git"},{"lessThan":"d3ef6c097ba078e1f8c7239d76a0ce8b61e75095","status":"affected","version":"befae75856ab406a3f3fab2aa2118cf3b2dfe3e6","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.2"},{"lessThan":"6.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc2","versionStartIncluding":"6.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: check_cond_jmp_op(): properly infer if register is null\n\nNicholas Carlini reported a bug when verifier can incorrectly infer\nthat a pointer is non-null. The bug occurs when two pointers are\ncompared and one of them has a type w/o PTR_MAYBE_NULL flag,\nbut which allows a value to be NULL at runtime.\nHere is an example:\n\n  // `a` is PTR_TO_MEM | MEM_RDONLY | PTR_UNTRUSTED\n  // `a` is 0 at runtime.\n  // `b` is PTR_TO_MAP_VALUE | PTR_MAYBE_NULL\n  void *a = bpf_rdonly_cast(0, 0);\n  int  *b = bpf_map_lookup_elem(...);\n\n  if (a == b)\n    *b = 42;  // verifier does not catch null pointer dereference\n\nThis happens because of a special case in check_cond_jmp_op(),\nwhich attempts to strip PTR_MAYBE_NULL flags from pointer types,\nwhen processing comparisons like `rA == rB`, if either rA or rB can't\nbe null.\n\nThe non-null property is derived based on the absence of\nPTR_MAYBE_NULL flag on rA's or rB's type. But that is not sufficient\nfor types like PTR_TO_MEM, as in the example.\n\nThis patch replaces type_may_be_null() call with reg_not_null(),\nwhich contains an allowlist of types for which absence of\nPTR_MAYBE_NULL actually means that the value can't be NULL at runtime.\n\nAt the moment, the list in the reg_not_null() omits two types for\nwhich PTR_MAYBE_NULL is applicable: PTR_TO_XDP_SOCK and PTR_TO_BUF.\nIn order to remain backward compatible, and assuming that only\ncomparison between pointers of the same type makes sense,\nthis commit extends reg_not_null(). W/o such an extension e.g.\nverifier_jeq_infer_not_null/null_ptr_to_map_value fails.\n\nreg_not_null() can be extended further, but I deem that out of scope\nfor the fix at hand. Explicit base_type(...) != PTR_TO_BTF_ID\nchecks in the check_cond_jmp_op() can be removed with migration to\nreg_not_null(), but that is a behavioural change, as the special case\nwould start matching for PTR_TO_BTF_ID that is also is_trusted_reg().\nI omit the behavioural change from this commit."}],"providerMetadata":{"dateUpdated":"2026-09-25T10:36:12.919Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/b55c9f019e169ed0d01394f96e172286a8b21b99"},{"url":"https://git.kernel.org/stable/c/d3ef6c097ba078e1f8c7239d76a0ce8b61e75095"}],"title":"bpf: check_cond_jmp_op(): properly infer if register is null","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-98134","datePublished":"2026-09-25T10:36:12.919Z","dateReserved":"2026-09-25T10:25:14.319Z","dateUpdated":"2026-09-25T10:36:12.919Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:44","lastModifiedDate":"2026-09-30 14:10:59","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"98134","Ordinal":"1","Title":"bpf: check_cond_jmp_op(): properly infer if register is null","CVE":"CVE-2026-98134","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"98134","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: check_cond_jmp_op(): properly infer if register is null\n\nNicholas Carlini reported a bug when verifier can incorrectly infer\nthat a pointer is non-null. The bug occurs when two pointers are\ncompared and one of them has a type w/o PTR_MAYBE_NULL flag,\nbut which allows a value to be NULL at runtime.\nHere is an example:\n\n  // `a` is PTR_TO_MEM | MEM_RDONLY | PTR_UNTRUSTED\n  // `a` is 0 at runtime.\n  // `b` is PTR_TO_MAP_VALUE | PTR_MAYBE_NULL\n  void *a = bpf_rdonly_cast(0, 0);\n  int  *b = bpf_map_lookup_elem(...);\n\n  if (a == b)\n    *b = 42;  // verifier does not catch null pointer dereference\n\nThis happens because of a special case in check_cond_jmp_op(),\nwhich attempts to strip PTR_MAYBE_NULL flags from pointer types,\nwhen processing comparisons like `rA == rB`, if either rA or rB can't\nbe null.\n\nThe non-null property is derived based on the absence of\nPTR_MAYBE_NULL flag on rA's or rB's type. But that is not sufficient\nfor types like PTR_TO_MEM, as in the example.\n\nThis patch replaces type_may_be_null() call with reg_not_null(),\nwhich contains an allowlist of types for which absence of\nPTR_MAYBE_NULL actually means that the value can't be NULL at runtime.\n\nAt the moment, the list in the reg_not_null() omits two types for\nwhich PTR_MAYBE_NULL is applicable: PTR_TO_XDP_SOCK and PTR_TO_BUF.\nIn order to remain backward compatible, and assuming that only\ncomparison between pointers of the same type makes sense,\nthis commit extends reg_not_null(). W/o such an extension e.g.\nverifier_jeq_infer_not_null/null_ptr_to_map_value fails.\n\nreg_not_null() can be extended further, but I deem that out of scope\nfor the fix at hand. Explicit base_type(...) != PTR_TO_BTF_ID\nchecks in the check_cond_jmp_op() can be removed with migration to\nreg_not_null(), but that is a behavioural change, as the special case\nwould start matching for PTR_TO_BTF_ID that is also is_trusted_reg().\nI omit the behavioural change from this commit.","Type":"Description","Title":"bpf: check_cond_jmp_op(): properly infer if register is null"}]}}}