CVE-2026-90159 PUBLISHED

bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks

_bpf_setsockopt() and _bpf_getsockopt() call sock_owned_by_me() for full sockets, so these helpers expect the socket lock to be held.

BPF_CGROUP_UNIX_GETPEERNAME and BPF_CGROUP_UNIX_GETSOCKNAME run BPF programs without acquiring the socket lock. A program attached to either hook can therefore trigger the sock_owned_by_me() warning by calling bpf_setsockopt() or bpf_getsockopt().

Disallow bpf_setsockopt() and bpf_getsockopt() for CGROUP_UNIX_GETPEERNAME and CGROUP_UNIX_GETSOCKNAME.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 859051dd165ec6cc915f0f2114699021144fd249 to 61769b9c882a964af3a6ebd9a8e43615f8713234 (excl.)
  • affected from 859051dd165ec6cc915f0f2114699021144fd249 to fe91c3f64a738dd97e8542ad5bdfbe5ac430edf6 (excl.)
  • affected from 859051dd165ec6cc915f0f2114699021144fd249 to daeb74f5f398e847d1d42906aec6610406a34fdc (excl.)
  • affected from 859051dd165ec6cc915f0f2114699021144fd249 to 84473a7e1813a2da7b759ab1d098a84998c8d3f5 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.7 is affected
  • unaffected from 0 to 6.7 (excl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References