Junglewise Threat Intelligence

CVE-2026-90317: Linux kernel BPF verifier use-after-free in RCU-protected pointers

CVE-2026-90317 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's BPF (Berkeley Packet Filter) subsystem allows user programs to run in the kernel with restricted capabilities. A flaw in the BPF verifier fails to invalidate kernel pointers after releasing a spin lock in sleepable BPF programs, allowing another CPU to free the underlying object before the pointer is dereferenced. This can lead to use-after-free vulnerabilities and kernel crashes or privilege escalation.

Technical details

The vulnerability exists in the BPF verifier (kernel/bpf/verifier.c) when handling sleepable BPF programs that use spin locks for RCU protection of kernel pointers (kptrs). When bpf_spin_unlock() is called, the verifier fails to invalidate RCU-protected pointers, leaving them valid in the register state. Another CPU can then free the underlying kernel object before the BPF program accesses it, resulting in a use-after-free. The fix tracks whether the program was in an RCU-protected context before releasing the lock and invalidates RCU-protected pointers only when exiting the final RCU context. The vulnerability was triggered in a runtime PoC causing task_struct use-after-free in __bpf_get_task_stack(). Requires capability to load BPF programs; patches are available in stable kernel branches.

Affected products

  • Linux Linux kernel All versions with sleepable BPF support (since 5861d1e8dbc4)

Timeline

  • 2026-09-17: disclosed
  • 2026-08-04: patched: Fix committed upstream; backported to stable branches

References

Related threats