PT-2026-94707 · Linux · Linux Kernel
CVE-2026-90359
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the BPF trampoline mechanism where return values exceeding 8 bytes are not fully preserved. Specifically, the
btf distill func proto() function allows 16-byte int128 return values, but the trampoline only preserves 8 bytes (such as the RAX register on x86). This leads to data corruption for the real caller and causes the attached program to observe only half of the return value. This affects struct ops and attach types that read the target return value, including fexit, fmod ret, and fsession (including their multi variants). The issue is handled within the bpf check attach target(), bpf check attach btf id multi(), and bpf struct ops desc init() functions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel