CVE-2026-90177 PUBLISHED

bpf: Check pointer type for all atomic RMW paths

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Check pointer type for all atomic RMW paths

Atomic RMW verification records an instruction pointer type only when the current destination is PTR_TO_ARENA. A second path can therefore reach the same instruction with an ordinary pointer without comparing it against the saved arena type.

The post-verification fixup uses the saved type to rewrite the instruction to BPF_PROBE_ATOMIC for every path. Record the actual destination type for all atomic RMW paths so the existing mismatch check rejects incompatible uses of one instruction.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d503a04f8bc0c75dc9db9452d8cc79d748afb752 to eb287c6e81dedef92da01eb947f380d0aae513c3 (excl.)
  • affected from d503a04f8bc0c75dc9db9452d8cc79d748afb752 to 4bc49ae344d65cfcef738f281ac575cf73ca2fc5 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.10 is affected
  • unaffected from 0 to 6.10 (excl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References