{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.111-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix NULL-ptr-deref in btf_var_show()  btf_var_show() calls btf_type_id_resolve() unconditionally, which dereferences btf-\u003eresolved_ids. That is NULL for a base BTF - e.g. the vmlinux BTF that bpf_snprintf_btf() renders against - since base BTF is not resolved during parsing. btf_modifier_show() guards this with 'if (btf-\u003eresolved_ids)', but btf_var_show() does not.  A BPF program that passes the type_id of a BTF_KIND_VAR from the vmlinux BTF to bpf_snprintf_btf() thus NULL-derefs:  KASAN: probably user-memory-access in range [0x46638-0x4663f] RIP: 0010:btf_var_show (kernel/bpf/btf.c:2929) Call Trace:  \u003cTASK\u003e  btf_type_show (kernel/bpf/btf.c:8259)  btf_type_snprintf_show (kernel/bpf/btf.c:8329)  bpf_snprintf_btf (kernel/trace/bpf_trace.c:1047)  bpf_prog_test_run_raw_tp (net/bpf/test_run.c:829)  __sys_bpf (kernel/bpf/syscall.c:4804)  do_syscall_64 (arch/x86/entry/syscall_64.c:84)  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)  \u003c/TASK\u003e  Resolve the var's type directly with btf_type_skip_modifiers() when resolved_ids is NULL, mirroring btf_modifier_show().",
  "id": "DEBIAN-CVE-2026-98063",
  "modified": "2026-09-29T10:47:36.733814033Z",
  "published": "2026-09-25T11:17:35.327Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98063"
    }
  ],
  "upstream": [
    "CVE-2026-98063"
  ]
}