PT-2026-94660 · Linux · Linux Kernel

CVE-2026-90312

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF subsystem where the check atomic load() function calls check load mem() before atomic ptr type ok(). In scenarios where a load-acquire operation fetches data into its own source register (dst reg == src reg), check load mem() overwrites the type of src reg with the type of the loaded value. Consequently, atomic ptr type ok() fails to identify and reject disallowed types such as ctx, pkt, flow keys, and sock.
Because bpf convert ctx accesses() does not rewrite atomic loads, raw access to underlying kernel objects remains. This leads to a type confusion where a register may be typed as PTR TO SOCK COMMON OR NULL while actually containing unconverted struct sk buff bytes, potentially allowing unauthorized access to kernel data after a NULL check is bypassed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90312
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel