Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Invalidate RCU pointers after final spin unlock

In a sleepable BPF program, a spin lock can provide the only RCU protection
for a kptr. The final bpf_spin_unlock() ends that protection, but the
verifier leaves the pointer valid. Another CPU can then free the object
before the pointer is used. A capability-limited runtime PoC triggered a
task_struct use-after-free in __bpf_get_task_stack().

Record whether the program is in an RCU-protected context before releasing
the lock. Invalidate RCU-protected pointers only when the unlock leaves the
final such context. This preserves valid pointers in non-sleepable programs
and inside an explicit RCU read-side section.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to kernel memory corruption
Action: Apply Patch
AI Analysis

Impact

A sleepable BPF program can acquire a spin lock that provides RCU protection for a kernel pointer. When the BPF verifier releases the lock via bpf_spin_unlock(), the RCU protection ends, but the verifier incorrectly keeps the pointer valid. This allows the kernel to free the object on another CPU before the pointer is dereferenced, producing a use‑after‑free of the task_struct in __bpf_get_task_stack(). The flaw can corrupt kernel memory if an attacker supplies a BPF program that triggers the scenario, potentially destabilizing the system. The weakness is an instance of CWE‑416 (Use After Free).

Affected Systems

All Linux kernel releases that shipped the BPF subsystem before the fix commit. Any kernel version where the BPF spin‑lock handling has not been patched is affected, including distribution‑specific kernels that have not applied the upstream update.

Risk and Exploitability

The CVSS score of 7.8 indicates a high impact if the flaw is exploited. The EPSS score of less than 1 % shows that real‑world exploitation is currently considered very unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to inject or execute a BPF program that uses a spin‑locked RCU pointer, which typically demands local or kernel‑privileged access or the capability to load BPF code. The exact attack vector—local, privilege escalation, or remote—is not explicitly documented in the description and is therefore inferred to be local or requiring the ability to load BPF programs.

Generated by OpenCVE AI on September 19, 2026 at 15:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the RCU pointer invalidation patch
  • Rebuild any custom kernel modules or distribution packages that depend on the BPF subsystem to ensure the fix is applied
  • If a kernel upgrade cannot be performed immediately, limit BPF program loading to trusted users or services by adjusting policy and reducing the capability for loading BPF code

Generated by OpenCVE AI on September 19, 2026 at 15:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Invalidate RCU pointers after final spin unlock In a sleepable BPF program, a spin lock can provide the only RCU protection for a kptr. The final bpf_spin_unlock() ends that protection, but the verifier leaves the pointer valid. Another CPU can then free the object before the pointer is used. A capability-limited runtime PoC triggered a task_struct use-after-free in __bpf_get_task_stack(). Record whether the program is in an RCU-protected context before releasing the lock. Invalidate RCU-protected pointers only when the unlock leaves the final such context. This preserves valid pointers in non-sleepable programs and inside an explicit RCU read-side section.
Title bpf: Invalidate RCU pointers after final spin unlock
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:32.573Z

Reserved: 2026-09-11T19:38:34.801Z

Link: CVE-2026-90317

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:29.580

Modified: 2026-09-18T18:17:53.437

Link: CVE-2026-90317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses