PT-2026-94741 · Linux · Linux Kernel

CVE-2026-90393

·

Published

2026-09-17

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the bpf netns link update prog() function. The issue occurs because checks for old prog and program type are performed without locking before the netns bpf mutex is acquired. If two threads concurrently execute BPF LINK UPDATE on the same network namespace link, it can lead to a Use-After-Free (UAF) condition, which happens when a program continues to use a memory pointer after it has been freed.
Recommendations Move the old prog and prog->type checks inside the netns bpf mutex critical section.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101897
CVE-2026-90393
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel