๐Ÿ” CVE Alert

CVE-2026-90393

UNKNOWN 0.0

bpf: Fix potential UAF in bpf_netns_link_update_prog

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF in bpf_netns_link_update_prog In bpf_netns_link_update_prog, the checks for old_prog and prog type are currently performed locklessly before acquiring netns_bpf_mutex. This creates a race condition that can lead to a UAF issue. If two threads concurrently execute BPF_LINK_UPDATE on the same netns link, the following execution path can trigger a UAF: CPU0 CPU1 bpf_netns_link_update_prog if (old_prog && old_prog != link->prog) return -EPERM; bpf_netns_link_update_prog if (old_prog && old_prog != link->prog) ... old_prog = xchg(&link->prog, new_prog); bpf_prog_put(old_prog); if (new_prog->type != link->prog->type) <-- trigger UAF Fix this by moving the old_prog and prog->type checks inside the netns_bpf_mutex critical section. Meanwhile, use guard() to simplify lock management and avoid all the goto jumping.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7f045a49fee04b5662cbdeaf0838f9322ae8c63a < d462b5481d77ce7df8a5ff89a699386f00c9214d 7f045a49fee04b5662cbdeaf0838f9322ae8c63a < bdddf3e1493ee973619c154a57071ce67f78598b 7f045a49fee04b5662cbdeaf0838f9322ae8c63a < 79a66fd997d4eecf17302d613194879eb32e0986 7f045a49fee04b5662cbdeaf0838f9322ae8c63a < f4ce6803df4095777191d800bebc50219b615ca0 7f045a49fee04b5662cbdeaf0838f9322ae8c63a < 277168cb9d153ce8e9c3f9275670e32ae61b41d6 7f045a49fee04b5662cbdeaf0838f9322ae8c63a < bda86e9f31b9a296b6e64a51c91dc776fc9f613e 7f045a49fee04b5662cbdeaf0838f9322ae8c63a < 923f559e95b89b33c7e1793b3d8f7f4ec9b2e4b7 7f045a49fee04b5662cbdeaf0838f9322ae8c63a < 5c5997836381010fc5907b36bc17d3b19407e933
Linux / Linux
5.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d462b5481d77ce7df8a5ff89a699386f00c9214d git.kernel.org: https://git.kernel.org/stable/c/bdddf3e1493ee973619c154a57071ce67f78598b git.kernel.org: https://git.kernel.org/stable/c/79a66fd997d4eecf17302d613194879eb32e0986 git.kernel.org: https://git.kernel.org/stable/c/f4ce6803df4095777191d800bebc50219b615ca0 git.kernel.org: https://git.kernel.org/stable/c/277168cb9d153ce8e9c3f9275670e32ae61b41d6 git.kernel.org: https://git.kernel.org/stable/c/bda86e9f31b9a296b6e64a51c91dc776fc9f613e git.kernel.org: https://git.kernel.org/stable/c/923f559e95b89b33c7e1793b3d8f7f4ec9b2e4b7 git.kernel.org: https://git.kernel.org/stable/c/5c5997836381010fc5907b36bc17d3b19407e933