PT-2026-94969 · Linux · Linux Kernel
CVE-2026-93173
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the BPF LSM component where
security bpf prog free() is called via bpf prog put rcu(), which serves as the call rcu() callback for non-sleepable programs. This sequence triggers bpf prog free within a softirq context. If a sleepable LSM program is attached to that hook, it triggers a might fault() BUG due to a sleeping function being called from an invalid context. The problem arises because the call rcu/call rcu tasks trace split is based on the sleepability of the freed program rather than the attached observer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel