SB2026091951 - Off-by-one in Linux kernel core
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Off-by-one (CVE-ID: CVE-2026-90160)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to an off-by-one headroom validation error in the lwt_bpf bpf_xmit() path when an LWT_XMIT BPF program modifies skb headroom. A local privileged user can call bpf_skb_change_head() to leave insufficient headroom and cause a denial of service.
On Ethernet, cached hardware-header output requires 16 bytes of headroom although the device hard-header length is 14 bytes.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/179a5b2171573d94a25c9aa8e1c9f9ac352ad316
- https://git.kernel.org/stable/c/5fe7007aed9ad069b2bd77e5d0c875c64f5c0269
- https://git.kernel.org/stable/c/753e5cdcca5474d230d62bb3489e5168ab27c272
- https://git.kernel.org/stable/c/7cf561843ed0ad57501892a65abb77957e6c800f
- https://git.kernel.org/stable/c/7d043e24520a273c362be5dd7d9c82796879a49b
- https://git.kernel.org/stable/c/a38c0eb447e2dd0120a2ebcdba470f9505ac8907
- https://git.kernel.org/stable/c/c488071c3441fa34f5a87cd6c12ce2cc6304f20e
- https://git.kernel.org/stable/c/de2b2004e16f2930eb689175e2c1998b0a68d499