Description
In the Linux kernel, the following vulnerability has been resolved:

bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks

__bpf_prog_put_rcu() is the call_rcu() callback for non-sleepable programs.
security_bpf_prog_free() called from there fires bpf_prog_free in softirq;
if a sleepable LSM prog is attached to that hook, might_fault() BUGs:

BUG: sleeping function called from invalid context
in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 5038
preempt_count: 101, expected: 0
Call Trace:
<IRQ>
__bpf_prog_enter_sleepable+0x1cd/0x320 kernel/bpf/trampoline.c:1255
bpf_trampoline_6442549705+0x53/0xd7
security_bpf_prog_free+0xde/0x130 security/security.c:5465
__bpf_prog_put_rcu+0xab/0xd0 kernel/bpf/syscall.c:2365
rcu_do_batch kernel/rcu/tree.c:2617 [inline]
handle_softirqs+0x236/0x800 kernel/softirq.c:622
</IRQ>

The call_rcu/call_rcu_tasks_trace split reflects the freed program's
sleepability, not that of any attached observer.

security_bpf_prog_free() also frees prog->aux->security, which has to stay
after the grace period, so drop bpf_prog_free from sleepable_lsm_hooks
rather than move the call. Non-sleepable observers still run there.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Oops due to invalid context usage in sleepable LSM BPF functions
Action: Immediate Update
AI Analysis

Impact

A bug in the Linux kernel arises when a sleepable LSM BPF program is freed in a softirq context. The kernel calls a function that performs a sleeping operation from a non‑sleepable context, triggering the built‑in BUG macro and resulting in a kernel panic or Oops. The failure is an implicit assertion violation caused by calling a sleeping function from an invalid context, leading to a loss of system stability and potential denial of service. No direct exploitation of privileges is disclosed, but the crash can be leveraged to destabilize services running on the affected host.

Affected Systems

All Linux kernel deployments that (or that may) use sleepable LSM BPF programs are impacted. The vulnerability was found in the core kernel code, affecting all mainstream Linux distributions that ship the standard kernel source tree. The CPE indicates the Linux kernel itself, and the vendor list lists Linux in general.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is provided, so the inherent severity is based on the kernel panic effect. The likely attack vector is the normal use of BPF programs with an LSM hook attached; an attacker with the ability to load or modify BPF bytecode could deliberately trigger the bug by enabling a sleepable LSM observer. Classic kernel debugging or monitoring mechanisms would reveal the BUG trigger in kernel logs.

Generated by OpenCVE AI on September 19, 2026 at 08:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the patch removing bpf_prog_free from sleepable_lsm_hooks
  • If an update is not immediately possible, refuse to load or attach sleepable LSM BPF programs to prevent the invalid context call
  • Continuously monitor kernel logs for BUG or oops messages and investigate any suspicious traces of the instability

Generated by OpenCVE AI on September 19, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-668
CWE-749

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks __bpf_prog_put_rcu() is the call_rcu() callback for non-sleepable programs. security_bpf_prog_free() called from there fires bpf_prog_free in softirq; if a sleepable LSM prog is attached to that hook, might_fault() BUGs: BUG: sleeping function called from invalid context in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 5038 preempt_count: 101, expected: 0 Call Trace: <IRQ> __bpf_prog_enter_sleepable+0x1cd/0x320 kernel/bpf/trampoline.c:1255 bpf_trampoline_6442549705+0x53/0xd7 security_bpf_prog_free+0xde/0x130 security/security.c:5465 __bpf_prog_put_rcu+0xab/0xd0 kernel/bpf/syscall.c:2365 rcu_do_batch kernel/rcu/tree.c:2617 [inline] handle_softirqs+0x236/0x800 kernel/softirq.c:622 </IRQ> The call_rcu/call_rcu_tasks_trace split reflects the freed program's sleepability, not that of any attached observer. security_bpf_prog_free() also frees prog->aux->security, which has to stay after the grace period, so drop bpf_prog_free from sleepable_lsm_hooks rather than move the call. Non-sleepable observers still run there.
Title bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:03.229Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93173

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:13.057

Modified: 2026-09-17T17:18:13.057

Link: CVE-2026-93173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:13Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere

  • CWE-749

    Exposed Dangerous Method or Function