Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90392NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix potential UAF when reading bpf link info

In bpf_link_show_fdinfo and bpf_link_get_info_by_fd, link->prog is
accessed without holding any locks. If the prog is concurrently replaced
via bpf_link_update, the old prog can be freed, leading to a potential
UAF issue.

Fix this by accessing link->prog under RCU protection to safely fetch
the pointer and guarantee its lifetime while reading its fields.
Severity Level
HIGH(7.8)
Published Date
Sep 17, 2026
Last Modified
Sep 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.16%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 7.8 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab and < a5c936ac904767fc1d943d40b0308bcb2ae2509b
  • Linux Linux >= 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab and < d7d7208e2603b45724b684f4df73904fb347741e
  • Linux Linux >= 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab and < 85cf991c881e7198be32be05a9daa2625390c8b3
  • Linux Linux >= 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab and < 79347e42cfbc9e78872922e8f08a70609c9af82f
  • Linux Linux >= 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab and < 863f3ddd0b8ac65abfb50d3be0869268ac0e277b
  • Linux Linux >= 5.7
Patched Versions
  • Linux Linux a5c936ac904767fc1d943d40b0308bcb2ae2509b
  • Linux Linux d7d7208e2603b45724b684f4df73904fb347741e
  • Linux Linux 85cf991c881e7198be32be05a9daa2625390c8b3
  • Linux Linux 79347e42cfbc9e78872922e8f08a70609c9af82f
  • Linux Linux 863f3ddd0b8ac65abfb50d3be0869268ac0e277b
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.