Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Check pointer type for all atomic RMW paths

Atomic RMW verification records an instruction pointer type only when the
current destination is PTR_TO_ARENA. A second path can therefore reach the
same instruction with an ordinary pointer without comparing it against the
saved arena type.

The post-verification fixup uses the saved type to rewrite the instruction
to BPF_PROBE_ATOMIC for every path. Record the actual destination type for
all atomic RMW paths so the existing mismatch check rejects incompatible
uses of one instruction.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via BPF type confusion
Action: Immediate Patch
AI Analysis

Impact

The defect originates in the Linux kernel’s BPF subsystem. An atomic read‑modify‑write instruction records the pointer type only when the destination is marked as a special arena pointer. A second execution path can reach the same instruction with an ordinary pointer that bypasses the earlier type check. After verification the instruction is rewritten to perform an atomic operation regardless of the actual pointer type. This mismatch allows a crafted BPF program to cause the kernel to treat an incompatible pointer as a valid atomic target, leading to unintended memory writes or corruption. Such memory corruption can be leveraged by an attacker to gain elevated privileges or crash the system.

Affected Systems

All Linux kernel binaries are affected. The CVE does not specify a vulnerable version range; any system running a kernel build that lacks the referenced patch commits is considered vulnerable.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via loading a BPF program that targets a userland process. Attackers would need privileged capabilities such as CAP_NET_ADMIN or CAP_SYS_ADMIN to load BPF programs; once loaded, the exploit runs in kernel context, giving the attacker the potential for kernel‑level privilege escalation or denial of service.

Generated by OpenCVE AI on September 20, 2026 at 01:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel release that contains the BPF atomic RMW pointer type check patch from the referenced Git commits.
  • Reboot to load the updated kernel image.
  • Configure the system to restrict BPF program loading, for example by setting the bpf_* sysctl parameters to zero or by removing the CAP_BPF capability from untrusted users.
  • If a patch is not available, isolate the system from untrusted BPF sources or disable the BPF subsystem entirely.

Generated by OpenCVE AI on September 20, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-272
CWE-704

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Check pointer type for all atomic RMW paths Atomic RMW verification records an instruction pointer type only when the current destination is PTR_TO_ARENA. A second path can therefore reach the same instruction with an ordinary pointer without comparing it against the saved arena type. The post-verification fixup uses the saved type to rewrite the instruction to BPF_PROBE_ATOMIC for every path. Record the actual destination type for all atomic RMW paths so the existing mismatch check rejects incompatible uses of one instruction.
Title bpf: Check pointer type for all atomic RMW paths
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:37.480Z

Reserved: 2026-09-11T19:38:34.791Z

Link: CVE-2026-90177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:11.623

Modified: 2026-09-18T18:17:45.693

Link: CVE-2026-90177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses
  • CWE-272

    Least Privilege Violation

  • CWE-704

    Incorrect Type Conversion or Cast