Executive brief
The Linux kernel's eBPF (extended Berkeley Packet Filter) subsystem contains a race condition vulnerability in network namespace link updates that can lead to use-after-free memory errors. An attacker with sufficient privileges could exploit this by triggering concurrent updates to the same BPF link, potentially causing a kernel crash or undefined behavior that could compromise system stability or security.
Technical details
A use-after-free (UAF) race condition exists in the bpf_netns_link_update_prog() function in kernel/bpf/net_namespace.c. The vulnerability arises because validity checks on old_prog and prog type are performed without holding the netns_bpf_mutex lock. If two threads concurrently execute BPF_LINK_UPDATE on the same netns link, the first thread can complete while the second thread still holds a reference to a freed program object, leading to a UAF when accessing link->prog->type after the program has been freed. The fix moves the checks inside the critical section protected by netns_bpf_mutex and refactors to use guard() for cleaner lock management. This vulnerability affects the Linux kernel's BPF subsystem and requires local/privileged access to trigger via BPF link operations.
Affected products
- Linux Linux kernel affected versions prior to commit 5c5997836381010fc5907b36bc17d3b19407e933
Timeline
- 2026-09-17: disclosed
- 2026-07-30: patched: Upstream fix committed by Andrii Nakryiko
- 2026-09-14: other: Stable tree backport merged by Greg Kroah-Hartman