PT-2026-94508 · Linux · Linux Kernel
CVE-2026-90160
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
lwt bpf component where the headroom check after an LWT XMIT BPF program is insufficient. The ip finish output2() function expands a socket buffer (skb) to LL RESERVED SPACE(dev) before transmission. If an LWT XMIT BPF program modifies the skb head using bpf skb change head(skb, 1, 0) and returns BPF OK, the subsequent recheck in bpf xmit() uses dst->dev->hard header len, which does not account for the aligned cache size required by neigh hh output(). For example, on Ethernet, while hard header len is 14 bytes, the cached copy requires 16 bytes. This discrepancy can lead to the skb being dropped due to a headroom warning in neigh hh output().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel