SB20260918355 - Use-after-free in Linux kernel bpf



SB20260918355 - Use-after-free in Linux kernel bpf

Published: September 18, 2026

Security Bulletin ID SB20260918355
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: CVE-2026-90317)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access a freed task_struct object.

The vulnerability exists due to improper handling of RCU-protected pointers in the BPF verifier when releasing the final BPF spin lock in a sleepable BPF program and subsequently using an RCU-protected kptr. A local user can execute a BPF program that uses an RCU-protected kptr after releasing its final spin lock to access a freed task_struct object.

The pointer remains valid to the verifier after the final lock release, allowing another CPU to free the referenced object before it is used.


Remediation

Install update from vendor's website.