PT-2026-94660 · Linux · Linux Kernel
CVE-2026-90312
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the BPF subsystem where the
check atomic load() function calls check load mem() before atomic ptr type ok(). In scenarios where a load-acquire operation fetches data into its own source register (dst reg == src reg), check load mem() overwrites the type of src reg with the type of the loaded value. Consequently, atomic ptr type ok() fails to identify and reject disallowed types such as ctx, pkt, flow keys, and sock.Because
bpf convert ctx accesses() does not rewrite atomic loads, raw access to underlying kernel objects remains. This leads to a type confusion where a register may be typed as PTR TO SOCK COMMON OR NULL while actually containing unconverted struct sk buff bytes, potentially allowing unauthorized access to kernel data after a NULL check is bypassed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel