Description
In the Linux kernel, the following vulnerability has been resolved:

bpf, cgroup: Fix storage null-ptr-deref after replacing prog

Syzkaller reported a storage null-ptr-deref issue after replacing prog.
This occurs in the following scenario:
1. prog A, an empty prog, is attached to a cgrp.
2. prog B uses BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE and calls the
bpf_get_local_storage helper.
3. link_update is called to replace prog A with prog B.

The reason is that __cgroup_bpf_replace fails to alloc and assign the
required cgrp storage for the incoming replacement prog. Consequently,
the new prog inherits an uninit storage, leading to null-ptr-deref panic
when kick the new prog.

Fix this by rejecting a link update if new_prog's cgroup storage is
incompatible with link->prog.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Crash)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the Linux kernel allows a null‑pointer dereference during a BPF program replacement in a cgroup context. When an empty program is replaced by a program that uses per‑CPU cgroup storage, the kernel fails to allocate the necessary storage for the new program, causing an uninitialized reference. If the replacement occurs, the kernel will panic, resulting in a denial‑of‑service condition for the entire system.

Affected Systems

All Linux kernel installations are potentially affected, as the issue resides in the core BPF and cgroup subsystems. The exact kernel versions are not enumerated, but any build that has not applied the patch is vulnerable.

Risk and Exploitability

The EPSS score indicates a very low likelihood of exploitation (<1 %). The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack likely requires a process with BPF loading permissions—typically root or a privileged user. Once executed, the kernel will crash, but achieving the replacement requires knowledge of the specific cgroup and BPF program context. The potential damage is high, yet the privileged nature of the required actions keeps the overall risk moderate to low in a hardened environment.

Generated by OpenCVE AI on September 19, 2026 at 03:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the fix for the storage null‑pointer dereference.
  • Reboot the system after applying the update to ensure the new kernel is active.
  • If the update cannot be applied immediately, avoid replacing BPF programs in cgroups that use per‑CPU group storage until the patch is installed.
  • Ensure that only trusted, high‑privilege processes perform BPF program link updates to mitigate risk during the interim.

Generated by OpenCVE AI on September 19, 2026 at 03:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix storage null-ptr-deref after replacing prog Syzkaller reported a storage null-ptr-deref issue after replacing prog. This occurs in the following scenario: 1. prog A, an empty prog, is attached to a cgrp. 2. prog B uses BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE and calls the bpf_get_local_storage helper. 3. link_update is called to replace prog A with prog B. The reason is that __cgroup_bpf_replace fails to alloc and assign the required cgrp storage for the incoming replacement prog. Consequently, the new prog inherits an uninit storage, leading to null-ptr-deref panic when kick the new prog. Fix this by rejecting a link update if new_prog's cgroup storage is incompatible with link->prog.
Title bpf, cgroup: Fix storage null-ptr-deref after replacing prog
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:51.403Z

Reserved: 2026-09-11T19:38:34.795Z

Link: CVE-2026-90250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:21.237

Modified: 2026-09-17T17:17:21.237

Link: CVE-2026-90250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:00:10Z

Weaknesses