← Back to CVE List
CVE-2026-90177NVD
Vulnerability Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Check pointer type for all atomic RMW paths
Atomic RMW verification records an instruction pointer type only when the
current destination is PTR_TO_ARENA. A second path can therefore reach the
same instruction with an ordinary pointer without comparing it against the
saved arena type.
The post-verification fixup uses the saved type to rewrite the instruction
to BPF_PROBE_ATOMIC for every path. Record the actual destination type for
all atomic RMW paths so the existing mismatch check rejects incompatible
uses of one instruction.
bpf: Check pointer type for all atomic RMW paths
Atomic RMW verification records an instruction pointer type only when the
current destination is PTR_TO_ARENA. A second path can therefore reach the
same instruction with an ordinary pointer without comparing it against the
saved arena type.
The post-verification fixup uses the saved type to rewrite the instruction
to BPF_PROBE_ATOMIC for every path. Record the actual destination type for
all atomic RMW paths so the existing mismatch check rejects incompatible
uses of one instruction.
CVSS v3.1 Base Metrics — Score 7.8 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Linux Linux >= d503a04f8bc0c75dc9db9452d8cc79d748afb752 and < eb287c6e81dedef92da01eb947f380d0aae513c3
- Linux Linux >= d503a04f8bc0c75dc9db9452d8cc79d748afb752 and < 4bc49ae344d65cfcef738f281ac575cf73ca2fc5
- Linux Linux >= 6.10
- Linux Linux eb287c6e81dedef92da01eb947f380d0aae513c3
- Linux Linux 4bc49ae344d65cfcef738f281ac575cf73ca2fc5