๐Ÿ” CVE Alert

CVE-2026-90317

UNKNOWN 0.0

bpf: Invalidate RCU pointers after final spin unlock

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Invalidate RCU pointers after final spin unlock In a sleepable BPF program, a spin lock can provide the only RCU protection for a kptr. The final bpf_spin_unlock() ends that protection, but the verifier leaves the pointer valid. Another CPU can then free the object before the pointer is used. A capability-limited runtime PoC triggered a task_struct use-after-free in __bpf_get_task_stack(). Record whether the program is in an RCU-protected context before releasing the lock. Invalidate RCU-protected pointers only when the unlock leaves the final such context. This preserves valid pointers in non-sleepable programs and inside an explicit RCU read-side section.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
5861d1e8dbc4e1a03ebffb96ac041026cdd34c07 < 7ae71629357d0a6d0bdadb929c7b296d5b7e61c2 5861d1e8dbc4e1a03ebffb96ac041026cdd34c07 < 180c7000712db77063b3a26f4c97e7dd9038f449
Linux / Linux
6.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/7ae71629357d0a6d0bdadb929c7b296d5b7e61c2 git.kernel.org: https://git.kernel.org/stable/c/180c7000712db77063b3a26f4c97e7dd9038f449