Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks

_bpf_setsockopt() and _bpf_getsockopt() call sock_owned_by_me() for
full sockets, so these helpers expect the socket lock to be held.

BPF_CGROUP_UNIX_GETPEERNAME and BPF_CGROUP_UNIX_GETSOCKNAME run BPF
programs without acquiring the socket lock. A program attached to
either hook can therefore trigger the sock_owned_by_me() warning by
calling bpf_setsockopt() or bpf_getsockopt().

Disallow bpf_setsockopt() and bpf_getsockopt() for CGROUP_UNIX_GETPEERNAME
and CGROUP_UNIX_GETSOCKNAME.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The bug allows a BPF program attached to the Linux kernel's cgroup UNIX getname hooks to call _bpf_setsockopt() or _bpf_getsockopt() without holding the socket lock that these helpers normally require. When executed in the hooks, the helpers trigger a sock_owned_by_me() warning, which can lead to a kernel fault and a system crash. The weakness is a race‐condition style flaw in the kernel's locking logic, and it can be categorized as a concurrent execution with shared resource issue.

Affected Systems

All Linux kernel builds that implement the cgroup UNIX getname hooks are potentially affected, as the CPE indicates a generic kernel version. No specific version constraints are listed in the CVE data, so any kernel revision that includes the getname hooks and has not been patched by the upstream commit is vulnerable.

Risk and Exploitability

The EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to load a BPF program attached to the CGROUP_UNIX_GETPEERNAME or CGROUP_UNIX_GETSOCKNAME hooks, which normally requires local user privileges or the ability to inject code with CAP_BPF. The vulnerability can result in denial of service through a kernel crash, but its exploitability is limited to environments where the attacker can control BPF program loading.

Generated by OpenCVE AI on September 20, 2026 at 02:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that disallows calling bpf_setsockopt() and bpf_getsockopt() within the CGROUP_UNIX_GETPEERNAME and CGROUP_UNIX_GETSOCKNAME hooks
  • If a patch is not yet available, disable or restrict the loading of BPF programs on these cgroup hooks by adjusting relevant sysctl settings or by revoking CAP_BPF from trusted users
  • Monitor kernel logs for sock_owned_by_me() warnings or warnings from BPF helper failures, and investigate any unexpected BPF activity

Generated by OpenCVE AI on September 20, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-368

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks _bpf_setsockopt() and _bpf_getsockopt() call sock_owned_by_me() for full sockets, so these helpers expect the socket lock to be held. BPF_CGROUP_UNIX_GETPEERNAME and BPF_CGROUP_UNIX_GETSOCKNAME run BPF programs without acquiring the socket lock. A program attached to either hook can therefore trigger the sock_owned_by_me() warning by calling bpf_setsockopt() or bpf_getsockopt(). Disallow bpf_setsockopt() and bpf_getsockopt() for CGROUP_UNIX_GETPEERNAME and CGROUP_UNIX_GETSOCKNAME.
Title bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:51.151Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:09.080

Modified: 2026-09-17T17:17:09.080

Link: CVE-2026-90159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-368

    Context Switching Race Condition