๐Ÿ” CVE Alert

CVE-2026-90210

UNKNOWN 0.0

bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure When bpf_trampoline_update() fails before modify_fentry_multi()/ unregister_fentry_multi() is called, cur_image is unchanged (cur_image == old_image) and ftrace still calls into it. Freeing old_image in that case causes a UAF. Only free old_image when it differs from cur_image.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
aef4dfa790b22d8052cfb78044eadbe03c876c39 < 65c3939656fd7848e9274faa07c26748b5bf049c aef4dfa790b22d8052cfb78044eadbe03c876c39 < 0253073fb7d79a2dd2eae9581ea16db2aef395a6
Linux / Linux
7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/65c3939656fd7848e9274faa07c26748b5bf049c git.kernel.org: https://git.kernel.org/stable/c/0253073fb7d79a2dd2eae9581ea16db2aef395a6