SB20260919184 - Improper handling of exceptional conditions in Linux kernel arm kernel



SB20260919184 - Improper handling of exceptional conditions in Linux kernel arm kernel

Published: September 19, 2026

Security Bulletin ID SB20260919184
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper handling of exceptional conditions (CVE-ID: CVE-2026-90306)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to prevent normal handling of userspace breakpoints.

The vulnerability exists due to incorrect handling of exceptional conditions in the ARM hardware breakpoint handler when processing userspace breakpoints of type 0x03 (ARM_ENTRY_CFI_BREAKPOINT). A local user can issue a breakpoint of this type from userspace to prevent normal handling of userspace breakpoints.

The behavior also occurs when kernel CFI instrumentation is disabled.


Remediation

Install update from vendor's website.