Junglewise Threat Intelligence

CVE-2026-90393: Linux kernel BPF use-after-free in netns link update

CVE-2026-90393 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's eBPF (extended Berkeley Packet Filter) subsystem contains a race condition vulnerability in network namespace link updates that can lead to use-after-free memory errors. An attacker with sufficient privileges could exploit this by triggering concurrent updates to the same BPF link, potentially causing a kernel crash or undefined behavior that could compromise system stability or security.

Technical details

A use-after-free (UAF) race condition exists in the bpf_netns_link_update_prog() function in kernel/bpf/net_namespace.c. The vulnerability arises because validity checks on old_prog and prog type are performed without holding the netns_bpf_mutex lock. If two threads concurrently execute BPF_LINK_UPDATE on the same netns link, the first thread can complete while the second thread still holds a reference to a freed program object, leading to a UAF when accessing link->prog->type after the program has been freed. The fix moves the checks inside the critical section protected by netns_bpf_mutex and refactors to use guard() for cleaner lock management. This vulnerability affects the Linux kernel's BPF subsystem and requires local/privileged access to trigger via BPF link operations.

Affected products

  • Linux Linux kernel affected versions prior to commit 5c5997836381010fc5907b36bc17d3b19407e933

Timeline

  • 2026-09-17: disclosed
  • 2026-07-30: patched: Upstream fix committed by Andrii Nakryiko
  • 2026-09-14: other: Stable tree backport merged by Greg Kroah-Hartman

References

Related threats