CVE-2026-90159
In the Linux kernel, the following vulnerability has been resolved:
bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks
_bpf_setsockopt() and _bpf_getsockopt() call sock_owned_by_me() for full sockets, so these helpers expect the socket lock to be held.
BPF_CGROUP_UNIX_GETPEERNAME and BPF_CGROUP_UNIX_GETSOCKNAME run BPF programs without acquiring the socket lock. A program attached to either hook can therefore trigger the sock_owned_by_me() warning by calling bpf_setsockopt() or bpf_getsockopt().
Disallow bpf_setsockopt() and bpf_getsockopt() for CGROUP_UNIX_GETPEERNAME and CGROUP_UNIX_GETSOCKNAME.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90159",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "859051dd165ec6cc915f0f2114699021144fd249",
"lessThan": "61769b9c882a964af3a6ebd9a8e43615f8713234",
"versionType": "git"
},
{
"status": "affected",
"version": "859051dd165ec6cc915f0f2114699021144fd249",
"lessThan": "fe91c3f64a738dd97e8542ad5bdfbe5ac430edf6",
"versionType": "git"
},
{
"status": "affected",
"version": "859051dd165ec6cc915f0f2114699021144fd249",
"lessThan": "daeb74f5f398e847d1d42906aec6610406a34fdc",
"versionType": "git"
},
{
"status": "affected",
"version": "859051dd165ec6cc915f0f2114699021144fd249",
"lessThan": "84473a7e1813a2da7b759ab1d098a84998c8d3f5",
"versionType": "git"
}
],
"programFiles": [
"net/core/filter.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/core/filter.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:09.080",
"references": [
{
"url": "https://git.kernel.org/stable/c/61769b9c882a964af3a6ebd9a8e43615f8713234",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/84473a7e1813a2da7b759ab1d098a84998c8d3f5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/daeb74f5f398e847d1d42906aec6610406a34fdc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fe91c3f64a738dd97e8542ad5bdfbe5ac430edf6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks\n\n_bpf_setsockopt() and _bpf_getsockopt() call sock_owned_by_me() for\nfull sockets, so these helpers expect the socket lock to be held.\n\nBPF_CGROUP_UNIX_GETPEERNAME and BPF_CGROUP_UNIX_GETSOCKNAME run BPF\nprograms without acquiring the socket lock. A program attached to\neither hook can therefore trigger the sock_owned_by_me() warning by\ncalling bpf_setsockopt() or bpf_getsockopt().\n\nDisallow bpf_setsockopt() and bpf_getsockopt() for CGROUP_UNIX_GETPEERNAME\nand CGROUP_UNIX_GETSOCKNAME."
}
],
"lastModified": "2026-09-17T17:17:09.080",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}