« Volver al listado

CVE-2026-90299

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix sleepable check for tracing/lsm prog

When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog is allowed to attach to '__x64_'-alike prefix symbols.

It is because the verifier does not verify whether the symbol is a kernel function or a bpf prog. That said, a sleepable tracing prog is allowed to attach to a bpf prog target whose name has '__x64_'-alike prefix.

For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP prog, and copies buffer from a user pointer with bpf_copy_from_user() helper. After attaching the XDP prog to lo interface, the kernel BUG could be triggered by 'ping -c 1 -W 1 127.0.0.1':

Leer descripción completaMostrar menos

Fix it by disallowing sleepable prog always when its target btf is not a kernel's btf.

Detalles técnicos trazas, registros y código del informe original
[    3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90299",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "16d9c5660692d6f0e6aba367274de2b6dfd4343c",
              "lessThan": "976f1be72740cfbc351d3841fd21186dda3ea723",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "16d9c5660692d6f0e6aba367274de2b6dfd4343c",
              "lessThan": "00244bdaa423d93f4571f3f6854378ce3365e524",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:27.403",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/00244bdaa423d93f4571f3f6854378ce3365e524",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/976f1be72740cfbc351d3841fd21186dda3ea723",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix sleepable check for tracing/lsm prog\n\nWhen CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog\nis allowed to attach to '__x64_'-alike prefix symbols.\n\nIt is because the verifier does not verify whether the symbol is a kernel\nfunction or a bpf prog. That said, a sleepable tracing prog is allowed to\nattach to a bpf prog target whose name has '__x64_'-alike prefix.\n\nFor example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP\nprog, and copies buffer from a user pointer with bpf_copy_from_user()\nhelper. After attaching the XDP prog to lo interface, the kernel BUG\ncould be triggered by 'ping -c 1 -W 1 127.0.0.1':\n\n[    3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324\n\nFix it by disallowing sleepable prog always when its target\nbtf is not a kernel's btf."
    }
  ],
  "lastModified": "2026-09-17T17:17:27.403",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}