Executive brief
The Linux kernel's eBPF (Berkeley Packet Filter) subsystem has a race condition in how it cleans up security programs when they are detached. When a sleepable Linux Security Module (LSM) program tries to run while the kernel is freeing a program from a softirq interrupt context, it triggers a kernel bug because the code attempts to sleep in a context where sleeping is forbidden. This can cause a system crash or denial of service.
Technical details
The vulnerability is a context switching bug in the eBPF LSM program lifecycle management. When __bpf_prog_put_rcu() is called as an RCU callback (in softirq context with preemption disabled), it invokes security_bpf_prog_free(), which in turn fires the bpf_lsm_bpf_prog_free LSM hook. If a sleepable LSM program is attached to that hook, __bpf_prog_enter_sleepable() calls might_fault(), which BUGs because sleeping is not allowed in softirq context. The fix removes bpf_prog_free from the sleepable_lsm_hooks list, allowing only non-sleepable observers to run there. The vulnerability affects the kernel's LSM infrastructure component and requires a system with eBPF LSM programs configured to trigger.
Affected products
- Linux Linux kernel Affected versions prior to kernel commit 2ce3f548cfc6a1fe4c53479cf8a21931cdfd51d8
Timeline
- 2026-09-17: disclosed: CVE-2026-93173 published
- 2026-07-01: patched: Upstream fix commit 2ce3f548cfc6a1fe4c53479cf8a21931cdfd51d8 by Sechang Lim