PT-2026-94707 · Linux · Linux Kernel

CVE-2026-90359

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF trampoline mechanism where return values exceeding 8 bytes are not fully preserved. Specifically, the btf distill func proto() function allows 16-byte int128 return values, but the trampoline only preserves 8 bytes (such as the RAX register on x86). This leads to data corruption for the real caller and causes the attached program to observe only half of the return value. This affects struct ops and attach types that read the target return value, including fexit, fmod ret, and fsession (including their multi variants). The issue is handled within the bpf check attach target(), bpf check attach btf id multi(), and bpf struct ops desc init() functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102201
CVE-2026-90359
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel