« Volver al listado

CVE-2026-90306

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9481/2: breakpoint: CFI breakpoints only on demand

This removes the stub hw_breakpoint_cfi_handler() from ARM, making it not steal breakpoint type 0x03 (ARM_ENTRY_CFI_BREAKPOINT) unless CFI is actively used in the kernel.

When not instrumenting with CFI, or when a breakpoint is issued in userspace, we fall through to return 1 from hw_breakpoint_pending() "unhandled fault" so userspace can make use of this breakpoint.

Tested with LKDTM and this command line: echo CFI_FORWARD_PROTO > /sys/kernel/debug/provoke-crash/DIRECT still works as expected.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90306",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c3f89986fde7bb9ccc86a901bf28e1f7d69fc3b3",
              "lessThan": "314f1a6762b5d51b37784ed7dc701d4c3d893703",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c3f89986fde7bb9ccc86a901bf28e1f7d69fc3b3",
              "lessThan": "da64b150e4b7bee615b33ab21f3137c31ec36922",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c3f89986fde7bb9ccc86a901bf28e1f7d69fc3b3",
              "lessThan": "8ed9bff906cf8036531d1559f10e82733a52b41f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm/kernel/hw_breakpoint.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm/kernel/hw_breakpoint.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:28.263",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/314f1a6762b5d51b37784ed7dc701d4c3d893703",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8ed9bff906cf8036531d1559f10e82733a52b41f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/da64b150e4b7bee615b33ab21f3137c31ec36922",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: 9481/2: breakpoint: CFI breakpoints only on demand\n\nThis removes the stub hw_breakpoint_cfi_handler() from ARM, making\nit not steal breakpoint type 0x03 (ARM_ENTRY_CFI_BREAKPOINT) unless\nCFI is actively used in the kernel.\n\nWhen not instrumenting with CFI, or when a breakpoint is issued in\nuserspace, we fall through to return 1 from hw_breakpoint_pending()\n\"unhandled fault\" so userspace can make use of this breakpoint.\n\nTested with LKDTM and this command line:\necho CFI_FORWARD_PROTO > /sys/kernel/debug/provoke-crash/DIRECT\nstill works as expected."
    }
  ],
  "lastModified": "2026-09-21T14:17:28.903",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}