CVE-2026-90392 PUBLISHED

bpf: Fix potential UAF when reading bpf link info

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix potential UAF when reading bpf link info

In bpf_link_show_fdinfo and bpf_link_get_info_by_fd, link->prog is accessed without holding any locks. If the prog is concurrently replaced via bpf_link_update, the old prog can be freed, leading to a potential UAF issue.

Fix this by accessing link->prog under RCU protection to safely fetch the pointer and guarantee its lifetime while reading its fields.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab to a5c936ac904767fc1d943d40b0308bcb2ae2509b (excl.)
  • affected from 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab to d7d7208e2603b45724b684f4df73904fb347741e (excl.)
  • affected from 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab to 85cf991c881e7198be32be05a9daa2625390c8b3 (excl.)
  • affected from 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab to 79347e42cfbc9e78872922e8f08a70609c9af82f (excl.)
  • affected from 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab to 863f3ddd0b8ac65abfb50d3be0869268ac0e277b (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.7 is affected
  • unaffected from 0 to 5.7 (excl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References