« Volver al listado

CVE-2026-90269

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject load-acquire from pointers requiring fault protection

A BPF_LOAD_ACQ is not rewritten to a BPF_PROBE_MEM load by the verifier, unlike a regular BPF_LDX, so the JIT emits a plain load with no exception table entry and a fault panics the kernel instead of being handled.

Reject the source pointer types that a BPF_LDX would have had that fault protection applied to, i.e. the ones bpf_convert_ctx_accesses() turns into BPF_PROBE_MEM: a bare PTR_TO_BTF_ID, PTR_TO_BTF_ID | PTR_UNTRUSTED, PTR_TO_BTF_ID | MEM_ALLOC | PTR_UNTRUSTED and PTR_TO_MEM | MEM_RDONLY | PTR_UNTRUSTED.

Leer descripción completaMostrar menos

This is reachable e.g. by loading ->mm out of a trusted task_struct yields an untrusted pointer to mm_struct, and it is NULL for a kernel thread:

Both dereference the same pointer, but only the BPF_LDX is protected (x86-64 JIT, jump targets shown prog-relative):

Note that BPF_PROBE_MEM is not visible in a bpftool xlated dump, as bpf_insn_prepare_dump() rewrites it back to BPF_MEM.

A PTR_TRUSTED pointer is deliberately not on the list. Such a load is not converted either, but it does not need to be, since the pointer is guaranteed live, so load-acquire from it stays allowed.

The check is gated on BPF_LOAD_ACQ so that atomic RMW and store-release error messages are unchanged; writes (RMW / store-release) to such pointers are already rejected elsewhere, so only load-acquire needs this.

Detalles técnicos trazas, registros y código del informe original
  [...]
  SEC("tp_btf/sched_switch")
  int BPF_PROG(demo, bool preempt, struct task_struct *prev,
               struct task_struct *next)
  {
      struct mm_struct *mm = next->mm;  /* untrusted */

      out_ldx = (__u64)mm->pgd;         /* BPF_LDX      */
      out_acq = load_acquire(&mm->pgd); /* BPF_LOAD_ACQ */
      return 0;
  }
  [...]

  [...]
  ; out_ldx = (__u64)mm->pgd;
  17:   movq    $-10485760, %r10
  1e:   movq    %rsi, %r11
  21:   addq    $184, %r11
  28:   subq    %r10, %r11
  2b:   movabsq $140737498841088, %r10
  35:   cmpq    %r10, %r11
  38:   ja      0x3e                 <-- kernel addr?
  3a:   xorl    %edi, %edi           <-- no: dst = 0, skip the load
  3c:   jmp     0x45
  3e:   movq    184(%rsi), %rdi      <-- yes: load + extable entry
  [...]
  ; load_acquire(&mm->pgd)
  53:	movq    %rsi, %rdi
  56:	movq    184(%rdi), %rax       <-- no check, no extable entry
  [...]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90269",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "880442305a3908589bf4d6fc1d79edb577ee497c",
              "lessThan": "c4c8de3bf48d3756ab0f910fe5cc4937d70efdcd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "880442305a3908589bf4d6fc1d79edb577ee497c",
              "lessThan": "5f8ade6e9b7931fc9697394f1b2c4ae833f5ac18",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "880442305a3908589bf4d6fc1d79edb577ee497c",
              "lessThan": "7db0a00445f1a40bacfe9b747405c11cb5f10fc9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:23.460",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5f8ade6e9b7931fc9697394f1b2c4ae833f5ac18",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7db0a00445f1a40bacfe9b747405c11cb5f10fc9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4c8de3bf48d3756ab0f910fe5cc4937d70efdcd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject load-acquire from pointers requiring fault protection\n\nA BPF_LOAD_ACQ is not rewritten to a BPF_PROBE_MEM load by the verifier,\nunlike a regular BPF_LDX, so the JIT emits a plain load with no exception\ntable entry and a fault panics the kernel instead of being handled.\n\nReject the source pointer types that a BPF_LDX would have had that fault\nprotection applied to, i.e. the ones bpf_convert_ctx_accesses() turns\ninto BPF_PROBE_MEM: a bare PTR_TO_BTF_ID, PTR_TO_BTF_ID | PTR_UNTRUSTED,\nPTR_TO_BTF_ID | MEM_ALLOC | PTR_UNTRUSTED and PTR_TO_MEM | MEM_RDONLY |\nPTR_UNTRUSTED.\n\nThis is reachable e.g. by loading ->mm out of a trusted task_struct\nyields an untrusted pointer to mm_struct, and it is NULL for a kernel\nthread:\n\n  [...]\n  SEC(\"tp_btf/sched_switch\")\n  int BPF_PROG(demo, bool preempt, struct task_struct *prev,\n               struct task_struct *next)\n  {\n      struct mm_struct *mm = next->mm;  /* untrusted */\n\n      out_ldx = (__u64)mm->pgd;         /* BPF_LDX      */\n      out_acq = load_acquire(&mm->pgd); /* BPF_LOAD_ACQ */\n      return 0;\n  }\n  [...]\n\nBoth dereference the same pointer, but only the BPF_LDX is protected\n(x86-64 JIT, jump targets shown prog-relative):\n\n  [...]\n  ; out_ldx = (__u64)mm->pgd;\n  17:   movq    $-10485760, %r10\n  1e:   movq    %rsi, %r11\n  21:   addq    $184, %r11\n  28:   subq    %r10, %r11\n  2b:   movabsq $140737498841088, %r10\n  35:   cmpq    %r10, %r11\n  38:   ja      0x3e                 <-- kernel addr?\n  3a:   xorl    %edi, %edi           <-- no: dst = 0, skip the load\n  3c:   jmp     0x45\n  3e:   movq    184(%rsi), %rdi      <-- yes: load + extable entry\n  [...]\n  ; load_acquire(&mm->pgd)\n  53:\tmovq    %rsi, %rdi\n  56:\tmovq    184(%rdi), %rax       <-- no check, no extable entry\n  [...]\n\nNote that BPF_PROBE_MEM is not visible in a bpftool xlated dump, as\nbpf_insn_prepare_dump() rewrites it back to BPF_MEM.\n\nA PTR_TRUSTED pointer is deliberately not on the list. Such a load is\nnot converted either, but it does not need to be, since the pointer is\nguaranteed live, so load-acquire from it stays allowed.\n\nThe check is gated on BPF_LOAD_ACQ so that atomic RMW and store-release\nerror messages are unchanged; writes (RMW / store-release) to such\npointers are already rejected elsewhere, so only load-acquire needs this."
    }
  ],
  "lastModified": "2026-09-17T17:17:23.460",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}