Junglewise Threat Intelligence

CVE-2026-90299: Linux kernel BPF verifier sleepable prog validation bypass

CVE-2026-90299 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's eBPF (Berkeley Packet Filter) subsystem contains a validation flaw that permits sleepable tracing programs to attach to non-kernel targets, leading to kernel crashes. Attackers with eBPF loading privileges could trigger a "BUG: sleeping function called from invalid context" crash by crafting malicious eBPF programs, resulting in denial of service and potential system instability.

Technical details

The vulnerability is a validation bypass in the BPF verifier's btf_id_allow_sleepable() function in kernel/bpf/verifier.c. When CONFIG_FUNCTION_ERROR_INJECTION is disabled, the verifier fails to check whether an attached target is a kernel function or a user-loaded eBPF program. This allows a sleepable fentry/tracing program to attach to any target with a kernel-like symbol name (e.g., '__x64_sys_nop'), including other eBPF programs. If such an attached program calls blocking helpers like bpf_copy_from_user(), it triggers a kernel BUG at trampoline.c:1324 due to sleeping in an invalid context. The fix adds a btf_is_kernel() check to reject sleepable programs when targeting non-kernel BTF objects. The vulnerability requires eBPF loading capability (typically CAP_BPF on modern kernels).

Affected products

  • Linux Linux Kernel Multiple versions prior to patch (2026-08-05); affects kernels with eBPF tracing/LSM support

Timeline

  • 2026-08-05: other: Patch committed by Andrii Nakryiko
  • 2026-09-17: disclosed

References

Related threats