Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix potential UAF in bpf_netns_link_update_prog

In bpf_netns_link_update_prog, the checks for old_prog and prog type
are currently performed locklessly before acquiring netns_bpf_mutex.
This creates a race condition that can lead to a UAF issue.

If two threads concurrently execute BPF_LINK_UPDATE on the same netns
link, the following execution path can trigger a UAF:

CPU0 CPU1
bpf_netns_link_update_prog
if (old_prog && old_prog != link->prog)
return -EPERM;
bpf_netns_link_update_prog
if (old_prog && old_prog != link->prog)
...
old_prog = xchg(&link->prog, new_prog);
bpf_prog_put(old_prog);
if (new_prog->type != link->prog->type) <-- trigger UAF

Fix this by moving the old_prog and prog->type checks inside the
netns_bpf_mutex critical section. Meanwhile, use guard() to simplify
lock management and avoid all the goto jumping.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in a BPF link update can corrupt kernel memory, potentially leading to a crash or privilege escalation
Action: Patch Immediately
AI Analysis

Impact

During a recent kernel modification, a race condition was identified in the BPF subsystem’s net‑namespace link update routine. The code performs checks on the existing program pointer and program type without holding the netns_bpf_mutex, permitting two threads to update the same link concurrently. One thread can replace the program pointer, free it, and allow the other thread to continue using the stale reference, producing a use‑after‑free. In a kernel context, such memory corruption can lead to silent data corruption, kernel crashes, or an attacker gaining elevated privileges through crafted BPF programs.

Affected Systems

The flaw exists in the Linux kernel source tree and will affect any distribution that ships a kernel containing the unpatched implementation. The issue is present across all vendors that ship the default Linux Kernel and does not have a targeted version string, so any kernel built from the pre‑commit source remains vulnerable until the patch is applied.

Risk and Exploitability

The EPSS score is below 1 %, indicating a low probability of current exploitation in the wild. The vulnerability is not in the CISA KEV catalog, which aligns with the historical detection of this bug. The use‑after‑free race requires the ability to submit BPF link update requests; an attacker would need local or privileged access to install malicious BPF functions or to trigger the race. While the attack surface is limited, the impact of a successful exploit could be a kernel crash or arbitrary code execution, making the flaw high‑impact if an attacker can meet the prerequisites.

Generated by OpenCVE AI on September 19, 2026 at 14:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a build that contains commit 277168cb9d153ce8e9c3f9275670e32ae61b41d6 or later, which protects the netns_bpf_mutex guard.
  • Reboot the system so that the patched kernel is loaded and active.
  • If an immediate kernel upgrade is not feasible, enforce that only processes with CAP_NET_ADMIN or equivalent can perform BPF link updates, effectively limiting the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF in bpf_netns_link_update_prog In bpf_netns_link_update_prog, the checks for old_prog and prog type are currently performed locklessly before acquiring netns_bpf_mutex. This creates a race condition that can lead to a UAF issue. If two threads concurrently execute BPF_LINK_UPDATE on the same netns link, the following execution path can trigger a UAF: CPU0 CPU1 bpf_netns_link_update_prog if (old_prog && old_prog != link->prog) return -EPERM; bpf_netns_link_update_prog if (old_prog && old_prog != link->prog) ... old_prog = xchg(&link->prog, new_prog); bpf_prog_put(old_prog); if (new_prog->type != link->prog->type) <-- trigger UAF Fix this by moving the old_prog and prog->type checks inside the netns_bpf_mutex critical section. Meanwhile, use guard() to simplify lock management and avoid all the goto jumping.
Title bpf: Fix potential UAF in bpf_netns_link_update_prog
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:26.388Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90393

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:38.903

Modified: 2026-09-17T17:17:38.903

Link: CVE-2026-90393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:30:16Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-416

    Use After Free