Improper locking in Linux kernel - CVE-2026-90046
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges or cause a kernel crash.
The vulnerability exists due to unsafe locking in the page allocator free path when BPF programs use affected features in NMI on non-SMP builds. A local user can execute BPF programs using these features in NMI to escalate privileges or cause a kernel crash.