« Volver al listado

CVE-2026-93173

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks

__bpf_prog_put_rcu() is the call_rcu() callback for non-sleepable programs. security_bpf_prog_free() called from there fires bpf_prog_free in softirq; if a sleepable LSM prog is attached to that hook, might_fault() BUGs:

The call_rcu/call_rcu_tasks_trace split reflects the freed program's sleepability, not that of any attached observer.

security_bpf_prog_free() also frees prog->aux->security, which has to stay after the grace period, so drop bpf_prog_free from sleepable_lsm_hooks rather than move the call. Non-sleepable observers still run there.

Detalles técnicos trazas, registros y código del informe original
  BUG: sleeping function called from invalid context
  in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 5038
  preempt_count: 101, expected: 0
  Call Trace:
   <IRQ>
   __bpf_prog_enter_sleepable+0x1cd/0x320 kernel/bpf/trampoline.c:1255
   bpf_trampoline_6442549705+0x53/0xd7
   security_bpf_prog_free+0xde/0x130 security/security.c:5465
   __bpf_prog_put_rcu+0xab/0xd0 kernel/bpf/syscall.c:2365
   rcu_do_batch kernel/rcu/tree.c:2617 [inline]
   handle_softirqs+0x236/0x800 kernel/softirq.c:622
   </IRQ>

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93173",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1b67772e4e3f16cd647b229cae95fc06d120be08",
              "lessThan": "2135f661fae7160a7fc603cab43cbc7999e8bfce",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1b67772e4e3f16cd647b229cae95fc06d120be08",
              "lessThan": "d5f2f741a900123fbcb7c7c0a002b81306fbe242",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1b67772e4e3f16cd647b229cae95fc06d120be08",
              "lessThan": "915c2d9d69fc6c5f9f41d12bf4a9c51293aaee62",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1b67772e4e3f16cd647b229cae95fc06d120be08",
              "lessThan": "2ce3f548cfc6a1fe4c53479cf8a21931cdfd51d8",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/bpf_lsm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/bpf_lsm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:13.057",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2135f661fae7160a7fc603cab43cbc7999e8bfce",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2ce3f548cfc6a1fe4c53479cf8a21931cdfd51d8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/915c2d9d69fc6c5f9f41d12bf4a9c51293aaee62",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d5f2f741a900123fbcb7c7c0a002b81306fbe242",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks\n\n__bpf_prog_put_rcu() is the call_rcu() callback for non-sleepable programs.\nsecurity_bpf_prog_free() called from there fires bpf_prog_free in softirq;\nif a sleepable LSM prog is attached to that hook, might_fault() BUGs:\n\n  BUG: sleeping function called from invalid context\n  in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 5038\n  preempt_count: 101, expected: 0\n  Call Trace:\n   <IRQ>\n   __bpf_prog_enter_sleepable+0x1cd/0x320 kernel/bpf/trampoline.c:1255\n   bpf_trampoline_6442549705+0x53/0xd7\n   security_bpf_prog_free+0xde/0x130 security/security.c:5465\n   __bpf_prog_put_rcu+0xab/0xd0 kernel/bpf/syscall.c:2365\n   rcu_do_batch kernel/rcu/tree.c:2617 [inline]\n   handle_softirqs+0x236/0x800 kernel/softirq.c:622\n   </IRQ>\n\nThe call_rcu/call_rcu_tasks_trace split reflects the freed program's\nsleepability, not that of any attached observer.\n\nsecurity_bpf_prog_free() also frees prog->aux->security, which has to stay\nafter the grace period, so drop bpf_prog_free from sleepable_lsm_hooks\nrather than move the call. Non-sleepable observers still run there."
    }
  ],
  "lastModified": "2026-09-17T17:18:13.057",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}