Junglewise Threat Intelligence

CVE-2026-53089: Linux kernel use-after-free in BPF offload info fill

CVE-2026-53089 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem could allow a local user to cause a system crash. The issue occurs when the system tries to access network information for certain hardware-offloaded programs while that network section is being deleted. This race condition leads to a 'use-after-free' error, which typically results in a kernel panic or system instability.

Technical details

A use-after-free vulnerability exists in kernel/bpf/offload.c within the bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() functions. The root cause is the use of get_net() on a network namespace (netns) whose reference count may have already reached zero during teardown. While rtnl_lock and bpf_devs_lock protect the netdev pointer, they do not prevent the underlying netns refcount from hitting zero, leading to a refcount_t increment on zero. An attacker with local access could potentially trigger this race condition to cause a kernel oops or denial of service. The fix replaces get_net() with maybe_get_net(), which safely handles zeroed reference counts by returning NULL.

Affected products

  • Linux Linux 4.16 to 7.0.10

Timeline

  • 2026-04-09: patched: Initial fix commit a0c584fc18056709c8e047a82a6045d6c209f4ce
  • 2026-06-24: disclosed: CVE published

References