Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90313NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed

A potential invalid storage access issue can occur after replacing a
cgroup bpf prog.

This occurs in the following scenario:
1. prog1 with storage is attached to a cgroup in multi-attach mode.
2. prog1 is replaced with prog2 using BPF_F_REPLACE in multi-attach
mode, but fails midway (e.g. in bpf_trampoline_link_cgroup_shim or
update_effective_progs).
3. A new prog3 is attached to the cgroup in multi-attach mode.

The reason is that __cgroup_bpf_attach overwrites pl->storage with the
new storage prior to attachment completion. When attachment fails
midway, the cleanup path calls bpf_cgroup_storages_free(new_storage) to
free the newly allocated storage, but fails to restore pl->storage back
to old_storage.

Consequently, the still-active prog1 holds invalid or dangling storage
pointers, leading to an invalid memory access when prog1 executes and
calls bpf_get_local_storage. Additionally, original pl->flags and
cgrp->bpf.flags[atype] are left unrestored.

Fix this by saving old_pl_flags, old_storage, and old_flags prior to the
update, and properly restoring all of them in the cleanup path on error.
Severity Level
UNKNOWN
Published Date
Sep 17, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.20%Probability
Root Weakness (CWE)
N/A

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 7d9c3427894fe70d1347b4820476bf37736d2ff0 and < e26db0d636e4c24a6b16683ea95cf5077c64d74b
  • Linux Linux >= 7d9c3427894fe70d1347b4820476bf37736d2ff0 and < aaca16e042527f7efe48b50799bc662f1a191ce1
  • Linux Linux >= 7d9c3427894fe70d1347b4820476bf37736d2ff0 and < 86ead176301109b78e1d14c0e9d0d9ff9723c769
  • Linux Linux >= 7d9c3427894fe70d1347b4820476bf37736d2ff0 and < 2c2218560b6e28a63ff7834ba26d09ff8efdee39
  • Linux Linux >= 7d9c3427894fe70d1347b4820476bf37736d2ff0 and < 6655c409707ec8ce9ce0850ffe4fe02331fd4d9c
  • Linux Linux >= 5.9
Patched Versions
  • Linux Linux e26db0d636e4c24a6b16683ea95cf5077c64d74b
  • Linux Linux aaca16e042527f7efe48b50799bc662f1a191ce1
  • Linux Linux 86ead176301109b78e1d14c0e9d0d9ff9723c769
  • Linux Linux 2c2218560b6e28a63ff7834ba26d09ff8efdee39
  • Linux Linux 6655c409707ec8ce9ce0850ffe4fe02331fd4d9c
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.