PT-2026-94447 · Linux · Linux Kernel

CVE-2026-90099

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description Unprivileged users can pin kernel memory outside of memory control group (memcg) charging. This occurs because allocations in the tc classifier * change() paths—including filter objects, per-CPU counters, and per-filter auxiliary data—use GFP KERNEL without the GFP ACCOUNT flag. Specifically, the shared tcf exts init ex() action array in cls api.c and allocations within cls basic, cls bpf, cls cgroup, cls flow, cls flower, cls fw, cls matchall, cls route, and cls u32 were unaccounted. Additionally, the u32 init knode() function in cls u32.c failed to account for knode allocations during the replace-path.
A separate issue exists in the cls basic error path where the basic change() function inserts fnew into the IDR before allocating a per-CPU counter. If alloc percpu() fails, the error path frees fnew without calling idr remove, resulting in a dangling pointer in the IDR.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102560
CVE-2026-90099
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel