CVE-2026-90217

Summary

In the Linux kernel, the following vulnerability has been resolved:

bpf: Compare iterator types during state pruning

An iterator stack slot can be MEM_RCU or PTR_UNTRUSTED. These states must not be equal, or the verifier can prune an unsafe path.

Compare the pointer type for STACK_ITER slots.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxdfab99df147b0d364f0c199f832ff2aedfb2265a < 6424b9cde9edc7f2098115bbfd1ee3d84a958380affected
LinuxLinuxdfab99df147b0d364f0c199f832ff2aedfb2265a < 83608e303b95d07afba1c15da0b5d9e513c2f15aaffected
LinuxLinux6.7affected
LinuxLinux0 < 6.7unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References