kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging improper use of pointers in place of scalars.
https://github.com/torvalds/linux/commit/179d1c5602997fef5a940c6ddcf31212cbfebd14