PT-2026-94508 · Linux · Linux Kernel

CVE-2026-90160

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the lwt bpf component where the headroom check after an LWT XMIT BPF program is insufficient. The ip finish output2() function expands a socket buffer (skb) to LL RESERVED SPACE(dev) before transmission. If an LWT XMIT BPF program modifies the skb head using bpf skb change head(skb, 1, 0) and returns BPF OK, the subsequent recheck in bpf xmit() uses dst->dev->hard header len, which does not account for the aligned cache size required by neigh hh output(). For example, on Ethernet, while hard header len is 14 bytes, the cached copy requires 16 bytes. This discrepancy can lead to the skb being dropped due to a headroom warning in neigh hh output().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102935
CVE-2026-90160
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel