Description
In the Linux kernel, the following vulnerability has been resolved:

bpf, xdp: move offload check into dev_xdp_install()

bpf_xdp_link_update() calls dev_xdp_install() directly and skips
dev_xdp_attach(), so the checks in dev_xdp_attach() do not run. A user can
make an XDP link with a normal program and then swap in an offloaded or
device-bound program with BPF_LINK_UPDATE, which puts it on the software
path.

dev_xdp_install() is the one place all three paths go through:
"ip link set xdp" and BPF_LINK_CREATE reach it via dev_xdp_attach(), and
BPF_LINK_UPDATE calls it directly. So move the program checks (offloaded,
bound to another device, device-bound in generic mode, native vs generic,
DEVMAP and CPUMAP) there, and keep only the netlink-flag check
(XDP_FLAGS_UPDATE_IF_NOEXIST) in dev_xdp_attach().
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s XDP (eXpress Data Path) handling. An XDP link created with a normal BPF program can later be updated to an offloaded or device‑bound program via BPF_LINK_UPDATE, bypassing the validation checks that normally run in dev_xdp_attach(). The missing checks allow the kernel to install an XDP program on the software path that is not intended for such execution, which can lead to incorrect packet processing, instability, or a crash. This flaw stems from improper enforcement of program type restrictions and offload requirements, making the kernel behave inconsistently with its documented design.

Affected Systems

Any system running a Linux kernel version prior to the patch that implements the fix in commit 03022dd874070768a7099f18b1944c633641315f is affected. The failure is in the core networking stack and applies to all builds that enable XDP (CONFIG_XDP) regardless of distribution or architecture. No explicit vendor or minor version is supplied, so any exposed Linux kernel is potentially impacted until the commit is deployed.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the EPSS score of less than 1% reflects a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, the wild at the time of analysis. A local user with the ability to create and update BPF XDP links can exploit the flaw; remote exploitation would require mechanisms to gain such access. If successfully leveraged, the flaw could result in a denial‑of‑service condition through kernel instability or unfiltered packet handling, but it does not provide a direct privilege escalation path.

Generated by OpenCVE AI on September 20, 2026 at 02:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes commit 03022dd874070768a7099f18b1944c633641315f, which moves all XDP program checks into dev_xdp_install().
  • As an interim measure, disable offloaded XDP programs or restrict BPF_LINK_UPDATE usage by removing or auditing such calls in the application code.
  • If updating is not immediately possible, enable logging for XDP activity (e.g., netlink messages) and monitor for anomalous errors or frequent crashes to detect exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf, xdp: move offload check into dev_xdp_install() bpf_xdp_link_update() calls dev_xdp_install() directly and skips dev_xdp_attach(), so the checks in dev_xdp_attach() do not run. A user can make an XDP link with a normal program and then swap in an offloaded or device-bound program with BPF_LINK_UPDATE, which puts it on the software path. dev_xdp_install() is the one place all three paths go through: "ip link set xdp" and BPF_LINK_CREATE reach it via dev_xdp_attach(), and BPF_LINK_UPDATE calls it directly. So move the program checks (offloaded, bound to another device, device-bound in generic mode, native vs generic, DEVMAP and CPUMAP) there, and keep only the netlink-flag check (XDP_FLAGS_UPDATE_IF_NOEXIST) in dev_xdp_attach().
Title bpf, xdp: move offload check into dev_xdp_install()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:23.835Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90146

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:07.490

Modified: 2026-09-18T18:17:43.987

Link: CVE-2026-90146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation