CVE-2026-90177

Summary

In the Linux kernel, the following vulnerability has been resolved:

bpf: Check pointer type for all atomic RMW paths

Atomic RMW verification records an instruction pointer type only when the current destination is PTR_TO_ARENA. A second path can therefore reach the same instruction with an ordinary pointer without comparing it against the saved arena type.

The post-verification fixup uses the saved type to rewrite the instruction to BPF_PROBE_ATOMIC for every path. Record the actual destination type for all atomic RMW paths so the existing mismatch check rejects incompatible uses of one instruction.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxd503a04f8bc0c75dc9db9452d8cc79d748afb752 < eb287c6e81dedef92da01eb947f380d0aae513c3affected
LinuxLinuxd503a04f8bc0c75dc9db9452d8cc79d748afb752 < 4bc49ae344d65cfcef738f281ac575cf73ca2fc5affected
LinuxLinux6.10affected
LinuxLinux0 < 6.10unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References