CVE-2026-90269
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject load-acquire from pointers requiring fault protection
A BPF_LOAD_ACQ is not rewritten to a BPF_PROBE_MEM load by the verifier, unlike a regular BPF_LDX, so the JIT emits a plain load with no exception table entry and a fault panics the kernel instead of being handled.
Reject the source pointer types that a BPF_LDX would have had that fault protection applied to, i.e. the ones bpf_convert_ctx_accesses() turns into BPF_PROBE_MEM: a bare PTR_TO_BTF_ID, PTR_TO_BTF_ID | PTR_UNTRUSTED, PTR_TO_BTF_ID | MEM_ALLOC | PTR_UNTRUSTED and PTR_TO_MEM | MEM_RDONLY | PTR_UNTRUSTED.
Leer descripción completaMostrar menos
This is reachable e.g. by loading ->mm out of a trusted task_struct yields an untrusted pointer to mm_struct, and it is NULL for a kernel thread:
Both dereference the same pointer, but only the BPF_LDX is protected (x86-64 JIT, jump targets shown prog-relative):
Note that BPF_PROBE_MEM is not visible in a bpftool xlated dump, as bpf_insn_prepare_dump() rewrites it back to BPF_MEM.
A PTR_TRUSTED pointer is deliberately not on the list. Such a load is not converted either, but it does not need to be, since the pointer is guaranteed live, so load-acquire from it stays allowed.
The check is gated on BPF_LOAD_ACQ so that atomic RMW and store-release error messages are unchanged; writes (RMW / store-release) to such pointers are already rejected elsewhere, so only load-acquire needs this.
Detalles técnicos trazas, registros y código del informe original
[...]
SEC("tp_btf/sched_switch")
int BPF_PROG(demo, bool preempt, struct task_struct *prev,
struct task_struct *next)
{
struct mm_struct *mm = next->mm; /* untrusted */
out_ldx = (__u64)mm->pgd; /* BPF_LDX */
out_acq = load_acquire(&mm->pgd); /* BPF_LOAD_ACQ */
return 0;
}
[...]
[...]
; out_ldx = (__u64)mm->pgd;
17: movq $-10485760, %r10
1e: movq %rsi, %r11
21: addq $184, %r11
28: subq %r10, %r11
2b: movabsq $140737498841088, %r10
35: cmpq %r10, %r11
38: ja 0x3e <-- kernel addr?
3a: xorl %edi, %edi <-- no: dst = 0, skip the load
3c: jmp 0x45
3e: movq 184(%rsi), %rdi <-- yes: load + extable entry
[...]
; load_acquire(&mm->pgd)
53: movq %rsi, %rdi
56: movq 184(%rdi), %rax <-- no check, no extable entry
[...]CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90269",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "880442305a3908589bf4d6fc1d79edb577ee497c",
"lessThan": "c4c8de3bf48d3756ab0f910fe5cc4937d70efdcd",
"versionType": "git"
},
{
"status": "affected",
"version": "880442305a3908589bf4d6fc1d79edb577ee497c",
"lessThan": "5f8ade6e9b7931fc9697394f1b2c4ae833f5ac18",
"versionType": "git"
},
{
"status": "affected",
"version": "880442305a3908589bf4d6fc1d79edb577ee497c",
"lessThan": "7db0a00445f1a40bacfe9b747405c11cb5f10fc9",
"versionType": "git"
}
],
"programFiles": [
"kernel/bpf/verifier.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"kernel/bpf/verifier.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:23.460",
"references": [
{
"url": "https://git.kernel.org/stable/c/5f8ade6e9b7931fc9697394f1b2c4ae833f5ac18",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7db0a00445f1a40bacfe9b747405c11cb5f10fc9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c4c8de3bf48d3756ab0f910fe5cc4937d70efdcd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject load-acquire from pointers requiring fault protection\n\nA BPF_LOAD_ACQ is not rewritten to a BPF_PROBE_MEM load by the verifier,\nunlike a regular BPF_LDX, so the JIT emits a plain load with no exception\ntable entry and a fault panics the kernel instead of being handled.\n\nReject the source pointer types that a BPF_LDX would have had that fault\nprotection applied to, i.e. the ones bpf_convert_ctx_accesses() turns\ninto BPF_PROBE_MEM: a bare PTR_TO_BTF_ID, PTR_TO_BTF_ID | PTR_UNTRUSTED,\nPTR_TO_BTF_ID | MEM_ALLOC | PTR_UNTRUSTED and PTR_TO_MEM | MEM_RDONLY |\nPTR_UNTRUSTED.\n\nThis is reachable e.g. by loading ->mm out of a trusted task_struct\nyields an untrusted pointer to mm_struct, and it is NULL for a kernel\nthread:\n\n [...]\n SEC(\"tp_btf/sched_switch\")\n int BPF_PROG(demo, bool preempt, struct task_struct *prev,\n struct task_struct *next)\n {\n struct mm_struct *mm = next->mm; /* untrusted */\n\n out_ldx = (__u64)mm->pgd; /* BPF_LDX */\n out_acq = load_acquire(&mm->pgd); /* BPF_LOAD_ACQ */\n return 0;\n }\n [...]\n\nBoth dereference the same pointer, but only the BPF_LDX is protected\n(x86-64 JIT, jump targets shown prog-relative):\n\n [...]\n ; out_ldx = (__u64)mm->pgd;\n 17: movq $-10485760, %r10\n 1e: movq %rsi, %r11\n 21: addq $184, %r11\n 28: subq %r10, %r11\n 2b: movabsq $140737498841088, %r10\n 35: cmpq %r10, %r11\n 38: ja 0x3e <-- kernel addr?\n 3a: xorl %edi, %edi <-- no: dst = 0, skip the load\n 3c: jmp 0x45\n 3e: movq 184(%rsi), %rdi <-- yes: load + extable entry\n [...]\n ; load_acquire(&mm->pgd)\n 53:\tmovq %rsi, %rdi\n 56:\tmovq 184(%rdi), %rax <-- no check, no extable entry\n [...]\n\nNote that BPF_PROBE_MEM is not visible in a bpftool xlated dump, as\nbpf_insn_prepare_dump() rewrites it back to BPF_MEM.\n\nA PTR_TRUSTED pointer is deliberately not on the list. Such a load is\nnot converted either, but it does not need to be, since the pointer is\nguaranteed live, so load-acquire from it stays allowed.\n\nThe check is gated on BPF_LOAD_ACQ so that atomic RMW and store-release\nerror messages are unchanged; writes (RMW / store-release) to such\npointers are already rejected elsewhere, so only load-acquire needs this."
}
],
"lastModified": "2026-09-17T17:17:23.460",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}