Answer in brief
CVE-2026-98059 records a Unknown severity vulnerability in bpf: Mark sched_process_wait argument as nullable. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b2fc4b17fc13810ef440fb323fad3981cd174985 <bee862c79cb7e0e5c33b2df2e3a31d164705120d || >=838a10bd2ebfe11a60dd67687533a7cfc220cc86 <3c03a1b8ded858685a73c1ba4080adef99db4544 || >=838a10bd2ebfe11a60dd67687533a7cfc220cc86 <b9205e936dde9a94e93376c8de6195b740bcd5d2 || >=838a10bd2ebfe11a60dd67687533a7cfc220cc86 <a453d6e3b8e8e1a321c8744d6189d763af9287d0 || >=6.12.6 <6.12.111 | bee862c79cb7e0e5c33b2df2e3a31d164705120d, 3c03a1b8ded858685a73c1ba4080adef99db4544, b9205e936dde9a94e93376c8de6195b740bcd5d2, a453d6e3b8e8e1a321c8744d6189d763af9287d0, 6.12.111 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Mark sched_process_wait argument as nullable do_wait() passes wo->wo_pid to the sched_process_wait tracepoint. kernel_wait4() leaves wo_pid NULL for wait4(-1), and kernel_waitid_prepare() does likewise for waitid(P_ALL). btf_ctx_access() currently types argument 0 as PTR_TO_BTF_ID | PTR_TRUSTED. Without PTR_MAYBE_NULL, the verifier accepts an unchecked dereference. Trusted pointer loads have no fault protection, so a wait for any child can then cause a NULL pointer dereference in JITed BPF code. Add sched_process_wait to raw_tp_null_args[] with argument 0 marked nullable. The verifier rejects an unchecked dereference while preserving access after the program checks the pointer for NULL.
Quoted source text, attributed separately from HOL analysis.