PT-2026-94969 · Linux · Linux Kernel

CVE-2026-93173

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF LSM component where security bpf prog free() is called via bpf prog put rcu(), which serves as the call rcu() callback for non-sleepable programs. This sequence triggers bpf prog free within a softirq context. If a sleepable LSM program is attached to that hook, it triggers a might fault() BUG due to a sleeping function being called from an invalid context. The problem arises because the call rcu/call rcu tasks trace split is based on the sleepability of the freed program rather than the attached observer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93173
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel