Incorrect behavior order in Linux kernel - CVE-2026-93173
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to improper execution-context handling in the bpf_prog_free hook of sleepable_lsm_hooks when a BPF program is freed while a sleepable LSM program is attached. A local privileged user can cause a BPF program to be freed to cause a denial of service.