Description
In the Linux kernel, the following vulnerability has been resolved:

bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed

A potential invalid storage access issue can occur after replacing a
cgroup bpf prog.

This occurs in the following scenario:
1. prog1 with storage is attached to a cgroup in multi-attach mode.
2. prog1 is replaced with prog2 using BPF_F_REPLACE in multi-attach
mode, but fails midway (e.g. in bpf_trampoline_link_cgroup_shim or
update_effective_progs).
3. A new prog3 is attached to the cgroup in multi-attach mode.

The reason is that __cgroup_bpf_attach overwrites pl->storage with the
new storage prior to attachment completion. When attachment fails
midway, the cleanup path calls bpf_cgroup_storages_free(new_storage) to
free the newly allocated storage, but fails to restore pl->storage back
to old_storage.

Consequently, the still-active prog1 holds invalid or dangling storage
pointers, leading to an invalid memory access when prog1 executes and
calls bpf_get_local_storage. Additionally, original pl->flags and
cgrp->bpf.flags[atype] are left unrestored.

Fix this by saving old_pl_flags, old_storage, and old_flags prior to the
update, and properly restoring all of them in the cleanup path on error.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch immediately
AI Analysis

Impact

The kernel’s BPF cgroup attach routine can leave a program with dangling storage references after a failed replacement operation, enabling an attacker to trigger invalid memory accesses when the program executes. This kernel memory corruption can lead to a crash or escalation of privileges if the attacker can control the replacement flow.

Affected Systems

All Linux kernel implementations are affected, as the vulnerability is present in the core kernel code handling BPF cgroup attachments. No specific kernel version ranges are listed, so any unpatched kernel is potentially vulnerable.

Risk and Exploitability

The EPSS score falls below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation today. However, the flaw requires the ability to load or replace BPF programs in cgroup contexts, which typically requires elevated privileges or kernel module access. The lack of a public exploit does not eliminate risk, as privileged users could inadvertently trigger a kernel crash or exploit the memory corruption to elevate privileges.

Generated by OpenCVE AI on September 19, 2026 at 04:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest version that includes the commit fixing the BPF cgroup attachment logic, as provided in the referenced kernel patches.
  • Restrict BPF program loading and replacement to trusted administrative accounts and enforce proper permission checks on cgroup operations to limit opportunities for misuse.
  • Ensure that BPF program replacement is performed only after the new program has fully linked and validated, preventing partial updates that could trigger dangling references.

Generated by OpenCVE AI on September 19, 2026 at 04:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-593

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed A potential invalid storage access issue can occur after replacing a cgroup bpf prog. This occurs in the following scenario: 1. prog1 with storage is attached to a cgroup in multi-attach mode. 2. prog1 is replaced with prog2 using BPF_F_REPLACE in multi-attach mode, but fails midway (e.g. in bpf_trampoline_link_cgroup_shim or update_effective_progs). 3. A new prog3 is attached to the cgroup in multi-attach mode. The reason is that __cgroup_bpf_attach overwrites pl->storage with the new storage prior to attachment completion. When attachment fails midway, the cleanup path calls bpf_cgroup_storages_free(new_storage) to free the newly allocated storage, but fails to restore pl->storage back to old_storage. Consequently, the still-active prog1 holds invalid or dangling storage pointers, leading to an invalid memory access when prog1 executes and calls bpf_get_local_storage. Additionally, original pl->flags and cgrp->bpf.flags[atype] are left unrestored. Fix this by saving old_pl_flags, old_storage, and old_flags prior to the update, and properly restoring all of them in the cleanup path on error.
Title bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:32.932Z

Reserved: 2026-09-11T19:38:34.801Z

Link: CVE-2026-90313

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:29.087

Modified: 2026-09-17T17:17:29.087

Link: CVE-2026-90313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:00:09Z

Weaknesses
  • CWE-593

    Authentication Bypass: OpenSSL CTX Object Modified after SSL Objects are Created