PT-2026-94741 · Linux · Linux Kernel
CVE-2026-90393
·
Published
2026-09-17
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists in the
bpf netns link update prog() function. The issue occurs because checks for old prog and program type are performed without locking before the netns bpf mutex is acquired. If two threads concurrently execute BPF LINK UPDATE on the same network namespace link, it can lead to a Use-After-Free (UAF) condition, which happens when a program continues to use a memory pointer after it has been freed.Recommendations
Move the
old prog and prog->type checks inside the netns bpf mutex critical section.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel