« Volver al listado

CVE-2026-90312

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Check load-acquire src ptr type before the load

check_atomic_load() calls check_load_mem() before atomic_ptr_type_ok(). For a load-acquire that fetches into its own source register (dst_reg == src_reg), check_load_mem() overwrites src_reg's type with the type of the loaded value, so the subsequent atomic_ptr_type_ok() no longer sees the source pointer and fails to reject the disallowed types (ctx, pkt, flow_keys, sock).

Since bpf_convert_ctx_accesses() does not rewrite atomic loads, the raw access to the underlying kernel object is left in place.

Leer descripción completaMostrar menos

The destination type is taken from the ctx access itself, so a load-acquire of the sk field of struct __sk_buff for example leaves the register typed as PTR_TO_SOCK_COMMON_OR_NULL, which type_is_sk_pointer() does not match either, while it actually holds unconverted struct sk_buff bytes. Once the NULL check has passed this is a type confusion, not just a leak of kernel data.

Validate src_reg with check_reg_arg() and check the source pointer type with atomic_ptr_type_ok() before the load again, mirroring check_atomic_rmw(). Out-of-range register numbers are already rejected earlier by check_and_resolve_insns() (commit 503d21ef8eac ("bpf: Do register range validation early")), and the only exemption there, is_stack_arg_ldx(), requires BPF_LDX | BPF_MEM | BPF_DW and thus never matches a BPF_ATOMIC insn. atomic_ptr_type_ok() can therefore not dereference register state out of bounds, that is, the out-of-bounds read addressed by the Fixes commit below does not reappear (as proven also via selftest).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) que omite validación de tipo en eBPF antes de carga, permitiendo type confusion y acceso a objetos kernel. Requiere escalada local (T1068) y confusión de tipos para ejecutar código o leer/manipular datos (T1059.004, T1005, T1565.001).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90312",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9",
              "lessThan": "6ee7b00888498cf387dd30729e18a05328b94709",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9",
              "lessThan": "422a416041172af1ac610736d5f556d22b31b115",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9",
              "lessThan": "b87803391baa7e0bef60549d8841f12e549ad057",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:28.977",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/422a416041172af1ac610736d5f556d22b31b115",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6ee7b00888498cf387dd30729e18a05328b94709",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b87803391baa7e0bef60549d8841f12e549ad057",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check load-acquire src ptr type before the load\n\ncheck_atomic_load() calls check_load_mem() before atomic_ptr_type_ok().\nFor a load-acquire that fetches into its own source register (dst_reg ==\nsrc_reg), check_load_mem() overwrites src_reg's type with the type of the\nloaded value, so the subsequent atomic_ptr_type_ok() no longer sees the\nsource pointer and fails to reject the disallowed types (ctx, pkt,\nflow_keys, sock).\n\nSince bpf_convert_ctx_accesses() does not rewrite atomic loads, the raw\naccess to the underlying kernel object is left in place. The destination\ntype is taken from the ctx access itself, so a load-acquire of the sk\nfield of struct __sk_buff for example leaves the register typed as\nPTR_TO_SOCK_COMMON_OR_NULL, which type_is_sk_pointer() does not match\neither, while it actually holds unconverted struct sk_buff bytes. Once\nthe NULL check has passed this is a type confusion, not just a leak of\nkernel data.\n\nValidate src_reg with check_reg_arg() and check the source pointer type\nwith atomic_ptr_type_ok() before the load again, mirroring\ncheck_atomic_rmw(). Out-of-range register numbers are already rejected\nearlier by check_and_resolve_insns() (commit 503d21ef8eac (\"bpf: Do\nregister range validation early\")), and the only exemption there,\nis_stack_arg_ldx(), requires BPF_LDX | BPF_MEM | BPF_DW and thus never\nmatches a BPF_ATOMIC insn. atomic_ptr_type_ok() can therefore not\ndereference register state out of bounds, that is, the out-of-bounds\nread addressed by the Fixes commit below does not reappear (as proven\nalso via selftest)."
    }
  ],
  "lastModified": "2026-09-18T18:17:53.130",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}