{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "b2fc4b17fc13810ef440fb323fad3981cd174985"
            },
            {
              "fixed": "bee862c79cb7e0e5c33b2df2e3a31d164705120d"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "838a10bd2ebfe11a60dd67687533a7cfc220cc86"
            },
            {
              "fixed": "3c03a1b8ded858685a73c1ba4080adef99db4544"
            },
            {
              "fixed": "b9205e936dde9a94e93376c8de6195b740bcd5d2"
            },
            {
              "fixed": "a453d6e3b8e8e1a321c8744d6189d763af9287d0"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.12.6"
            },
            {
              "fixed": "6.12.111"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.111"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.53"
            },
            {
              "fixed": "7.2.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98059.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mark sched_process_wait argument as nullable\n\ndo_wait() passes wo-\u003ewo_pid to the sched_process_wait tracepoint.\nkernel_wait4() leaves wo_pid NULL for wait4(-1), and\nkernel_waitid_prepare() does likewise for waitid(P_ALL).\n\nbtf_ctx_access() currently types argument 0 as PTR_TO_BTF_ID |\nPTR_TRUSTED. Without PTR_MAYBE_NULL, the verifier accepts an unchecked\ndereference. Trusted pointer loads have no fault protection, so a wait for\nany child can then cause a NULL pointer dereference in JITed BPF code.\n\nAdd sched_process_wait to raw_tp_null_args[] with argument 0 marked\nnullable. The verifier rejects an unchecked dereference while preserving\naccess after the program checks the pointer for NULL.",
  "id": "CVE-2026-98059",
  "modified": "2026-09-27T03:30:32.996736986Z",
  "published": "2026-09-25T10:24:04.788Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/3c03a1b8ded858685a73c1ba4080adef99db4544"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a453d6e3b8e8e1a321c8744d6189d763af9287d0"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b9205e936dde9a94e93376c8de6195b740bcd5d2"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/bee862c79cb7e0e5c33b2df2e3a31d164705120d"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98059.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98059"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "bpf: Mark sched_process_wait argument as nullable"
}