SB2026091964 - Signed to Unsigned Conversion Error in Linux kernel bpf
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-90157)
CWE-ID: CWE-195 - Signed to Unsigned Conversion Error
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a hardened usercopy warning.
The vulnerability exists due to an improper signed-to-unsigned conversion in __cgroup_bpf_run_filter_getsockopt_kern() when a cgroup getsockopt BPF program modifies ctx.optlen after the kernel getsockopt handler has run. A local user can set ctx.optlen to a negative value to trigger a hardened usercopy warning.
The issue affects the kernel-buffer getsockopt path used by TCP_ZEROCOPY_RECEIVE.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1b5aacd5b2419b0790e955e466d389a61c79b4b1
- https://git.kernel.org/stable/c/2bdbe00454200fcb0110f31eeca8d906a3515e74
- https://git.kernel.org/stable/c/31a89af4f513d750fec196e2bb6195a7d4473e9f
- https://git.kernel.org/stable/c/554ba7195c4108726450e24480c8449990c2268c
- https://git.kernel.org/stable/c/5b09d984b38b018b123c3a9e02a96bbc6468dbe5
- https://git.kernel.org/stable/c/d02a12b4085ffe41ea750b1007f7a9c7aee2875a
- https://git.kernel.org/stable/c/e6fbf0eba87f50084d67508898f6ad6fc7ff1ba2
- https://git.kernel.org/stable/c/f68671b1a98d426c57864bd457c125fee14ac1a5