Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix sleepable check for tracing/lsm prog

When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog
is allowed to attach to '__x64_'-alike prefix symbols.

It is because the verifier does not verify whether the symbol is a kernel
function or a bpf prog. That said, a sleepable tracing prog is allowed to
attach to a bpf prog target whose name has '__x64_'-alike prefix.

For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP
prog, and copies buffer from a user pointer with bpf_copy_from_user()
helper. After attaching the XDP prog to lo interface, the kernel BUG
could be triggered by 'ping -c 1 -W 1 127.0.0.1':

[ 3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324

Fix it by disallowing sleepable prog always when its target
btf is not a kernel's btf.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash leading to denial of service
Action: Immediate Patch
AI Analysis

Impact

An attacker can exploit a flaw in the Linux kernel's BPF verifier that fails to confirm whether a symbol is a kernel function or another BPF program when CONFIG_FUNCTION_ERROR_INJECTION is disabled. This oversight permits a sleepable tracing program to attach to a BPF program whose name carries an __x64_ prefix. Once attached, the tracing program can invoke bpf_copy_from_user on a user pointer in an inappropriate execution context. This sequence can trigger a BUG in kernel/bpf/trampoline.c, resulting in a kernel panic. The impact is a denial of service that can crash the entire system, exposing all processes and data to interruption. The flaw is best classified as a type mismatch/incorrect verification weakness (CWE-704).

Affected Systems

Linux kernel binaries compiled with the default configuration that has CONFIG_FUNCTION_ERROR_INJECTION disabled are affected. No specific version range is listed in the advisory, implying that the vulnerability exists in recent kernel releases that contain the flawed verifier logic until the patch is applied. All organizations running a Linux distribution that relies on the upstream kernel or a derivative that preserves this code path must consider the update.

Risk and Exploitability

The vulnerability has an EPSS score of less than 1%, indicating a very low probability of exploitation. It is not listed in the CISA KEV catalog, suggesting no confirmed active exploitation. The reported attack likely requires an attacker to be able to load a custom BPF program, which could be accomplished locally or via elevated privileges in remote exploitation. In the absence of privileged access, the risk remains limited, but the potential for a system-wide crash remains significant if the flaw is exploited.

Generated by OpenCVE AI on September 19, 2026 at 14:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the kernel update that includes the fix for CVE-2026-90299, or rebuild the kernel with the latest patch set.
  • If a patch is not immediately available, enable CONFIG_FUNCTION_ERROR_INJECTION in the kernel configuration to force the verifier to check symbol types, or disable any sleepable tracing programs that target __x64_ prefixed symbols.
  • As a temporary measure, avoid attaching sleepable BPF tracing programs to kernel symbols with an __x64_ prefix by removing or reconfiguring these programs.

Generated by OpenCVE AI on September 19, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-704

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix sleepable check for tracing/lsm prog When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog is allowed to attach to '__x64_'-alike prefix symbols. It is because the verifier does not verify whether the symbol is a kernel function or a bpf prog. That said, a sleepable tracing prog is allowed to attach to a bpf prog target whose name has '__x64_'-alike prefix. For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP prog, and copies buffer from a user pointer with bpf_copy_from_user() helper. After attaching the XDP prog to lo interface, the kernel BUG could be triggered by 'ping -c 1 -W 1 127.0.0.1': [ 3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324 Fix it by disallowing sleepable prog always when its target btf is not a kernel's btf.
Title bpf: Fix sleepable check for tracing/lsm prog
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:23.888Z

Reserved: 2026-09-11T19:38:34.799Z

Link: CVE-2026-90299

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:27.403

Modified: 2026-09-17T17:17:27.403

Link: CVE-2026-90299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:45:14Z

Weaknesses
  • CWE-704

    Incorrect Type Conversion or Cast