Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Compare iterator types during state pruning

An iterator stack slot can be MEM_RCU or PTR_UNTRUSTED. These states
must not be equal, or the verifier can prune an unsafe path.

Compare the pointer type for STACK_ITER slots.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel‑Mode Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The BPF verifier in the Linux kernel erroneously treats MEM_RCU and PTR_UNTRUSTED iterator stack slots as equal. This miscomparison allows the verifier to prune an unsafe path incorrectly, enabling carefully crafted eBPF programs to execute kernel operations that are normally prohibited. The consequence is kernel‑mode code execution, effectively granting an attacker elevated privileges within the kernel.

Affected Systems

The bug resides in the Linux kernel BPF subsystem and affects all kernel releases that incorporate the unpatched verifier logic. Since the advisory does not list specific releases, all current and prior Linux kernel versions lacking the patch are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8. EPSS score of less than 1% suggests a low probability of widespread exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would need the capability to load eBPF programs, a function that typically requires CAP_SYS_ADMIN or root access. Based on the description, it is inferred that such privilege is necessary before the vulnerability can be exercised. Once a program is accepted, the malformed verifier bypass can lead to arbitrary kernel code execution.

Generated by OpenCVE AI on September 20, 2026 at 03:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the BPF verifier patch for CVE‑2026‑90217.
  • Reboot the system to activate the updated kernel.
  • If eBPF functionality is unnecessary, disable BPF support by removing the corresponding module from the kernel configuration or passing boot parameters to prevent BPF usage until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-665

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Compare iterator types during state pruning An iterator stack slot can be MEM_RCU or PTR_UNTRUSTED. These states must not be equal, or the verifier can prune an unsafe path. Compare the pointer type for STACK_ITER slots.
Title bpf: Compare iterator types during state pruning
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:48.672Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90217

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:17.033

Modified: 2026-09-18T18:17:46.850

Link: CVE-2026-90217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses