Description
In the Linux kernel, the following vulnerability has been resolved:

net: kcm: Hold RCU read lock while running BPF parser

kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which
prevents CPU migration, but does not establish an RCU read-side
critical section. Consequently, BPF map operations can trigger
WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser
program.

Hold the RCU read lock while running the program.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential kernel warning and instability
Action: Patch update
AI Analysis

Impact

A kernel bug allows the KCM string parser to execute a BPF program using bpf_prog_run_pin_on_cpu() without establishing an RCU read‑side critical section. The missing RCU lock permits CPU migration during BPF execution, and when the BPF program performs map operations it triggers the kernel warning WARN_ON_ONCE(!bpf_rcu_lock_held()). The warning indicates a breach of RCU invariants and could signal a condition that may lead to kernel instability if the race is exploited.

Affected Systems

All Linux kernel builds that have not yet incorporated the recent patch that adds an RCU read lock around BPF execution in the KCM string parser. The vendor data does not specify exact version ranges, so any kernel version prior to the release of the fix remains exposed.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of automated exploitation. Attackers would need to supply a malicious BPF program or otherwise trigger the KCM strparser in a context where user‑supplied BPF code is executed, which typically requires elevated privileges or compromised user space. While the immediate impact is limited to a warning that may precede instability, the risk is elevated if an attacker can repeatedly trigger the condition. The CVSS score of 7.8 classifies this as a high‑severity vulnerability.

Generated by OpenCVE AI on September 20, 2026 at 03:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the RCU lock fix for KCM BPF execution.
  • If a kernel upgrade is not immediately possible, disable the KCM strparser feature or restrict the execution of BPF programs in that context until the kernel is patched.
  • Continuously monitor kernel logs for WARN_ON_ONCE(!bpf_rcu_lock_held()) messages and investigate any occurrences promptly.

Generated by OpenCVE AI on September 20, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parser kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents CPU migration, but does not establish an RCU read-side critical section. Consequently, BPF map operations can trigger WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser program. Hold the RCU read lock while running the program.
Title net: kcm: Hold RCU read lock while running BPF parser
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:21.163Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90143

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:07.097

Modified: 2026-09-18T18:17:43.690

Link: CVE-2026-90143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:15:08Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')