Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix potential UAF when reading bpf link info

In bpf_link_show_fdinfo and bpf_link_get_info_by_fd, link->prog is
accessed without holding any locks. If the prog is concurrently replaced
via bpf_link_update, the old prog can be freed, leading to a potential
UAF issue.

Fix this by accessing link->prog under RCU protection to safely fetch
the pointer and guarantee its lifetime while reading its fields.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free in Linux kernel BPF link subsystem
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s BPF link subsystem contains a race condition in bpf_link_show_fdinfo and bpf_link_get_info_by_fd where a pointer to a BPF program (link->prog) is accessed without holding a lock. If a concurrent bpf_link_update frees the old program, the pointer becomes dangling, potentially allowing a use‑after‑free that can corrupt kernel memory or cause a crash. The vulnerability is explicitly a use‑after‑free flaw that could lead to kernel memory corruption, denial of service, or other unintended kernel execution behavior.

Affected Systems

All Linux kernel builds that include the BPF link subsystem but do not yet incorporate the RCU‑protected access introduced in commit 79347e42f are affected. In practice this means every mainstream kernel release prior to that commit, effectively covering the majority of production systems unless they have applied the patch or are running a newer kernel version.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level, while the EPSS score of less than 1% shows a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that exploitation requires local or privileged access capable of creating or updating BPF links, after which the race can be triggered to cause kernel memory corruption or a crash.

Generated by OpenCVE AI on September 20, 2026 at 01:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes commit 79347e42f and later, thereby protecting link->prog access with RCU.
  • Reboot the system after updating so the patched kernel takes effect.
  • As a temporary measure, limit BPF link creation and modification by tightening SELinux/AppArmor policies or disabling related sysctl knobs to restrict which users can perform bpf_link_update.

Generated by OpenCVE AI on September 20, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF when reading bpf link info In bpf_link_show_fdinfo and bpf_link_get_info_by_fd, link->prog is accessed without holding any locks. If the prog is concurrently replaced via bpf_link_update, the old prog can be freed, leading to a potential UAF issue. Fix this by accessing link->prog under RCU protection to safely fetch the pointer and guarantee its lifetime while reading its fields.
Title bpf: Fix potential UAF when reading bpf link info
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:04.014Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90392

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:38.790

Modified: 2026-09-18T18:17:56.940

Link: CVE-2026-90392

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses