PT-2026-94525 · Linux · Linux Kernel

CVE-2026-90177

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF (Berkeley Packet Filter) subsystem regarding atomic Read-Modify-Write (RMW) verification. The system only records the instruction pointer type when the destination is PTR TO ARENA, allowing a second execution path to reach the same instruction with an ordinary pointer without verifying it against the saved arena type. This occurs because the post-verification fixup rewrites instructions to BPF PROBE ATOMIC for every path based on the saved type, potentially leading to incompatible instruction usage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90177
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel