๐Ÿ” CVE Alert

CVE-2026-90146

UNKNOWN 0.0

bpf, xdp: move offload check into dev_xdp_install()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf, xdp: move offload check into dev_xdp_install() bpf_xdp_link_update() calls dev_xdp_install() directly and skips dev_xdp_attach(), so the checks in dev_xdp_attach() do not run. A user can make an XDP link with a normal program and then swap in an offloaded or device-bound program with BPF_LINK_UPDATE, which puts it on the software path. dev_xdp_install() is the one place all three paths go through: "ip link set xdp" and BPF_LINK_CREATE reach it via dev_xdp_attach(), and BPF_LINK_UPDATE calls it directly. So move the program checks (offloaded, bound to another device, device-bound in generic mode, native vs generic, DEVMAP and CPUMAP) there, and keep only the netlink-flag check (XDP_FLAGS_UPDATE_IF_NOEXIST) in dev_xdp_attach().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
026a4c28e1db3b0cb99cd9a3e495d4a8b632fa74 < ea7b35dcc9430293b861bc7bad0c546f193c85f9 026a4c28e1db3b0cb99cd9a3e495d4a8b632fa74 < 03022dd874070768a7099f18b1944c633641315f 026a4c28e1db3b0cb99cd9a3e495d4a8b632fa74 < ad27ed7d2309419a129078d781504f486b1b469a
Linux / Linux
5.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ea7b35dcc9430293b861bc7bad0c546f193c85f9 git.kernel.org: https://git.kernel.org/stable/c/03022dd874070768a7099f18b1944c633641315f git.kernel.org: https://git.kernel.org/stable/c/ad27ed7d2309419a129078d781504f486b1b469a