The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of invalid variable stack read operations.
https://github.com/torvalds/linux/commit/ea25f914dc164c8d56b36147ecc86bc65f83c469