Use-after-free in Linux kernel - CVE-2026-90313
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to trigger an invalid memory access.
The vulnerability exists due to use-after-free in __cgroup_bpf_attach when replacing a cgroup BPF program in multi-attach mode and the attachment fails midway. A local user can perform a failed BPF_F_REPLACE operation and attach another cgroup BPF program to trigger an invalid memory access.
The issue requires an active replaced program with local storage to execute bpf_get_local_storage after the failed attachment.
Affected software
How to mitigate CVE-2026-90313
External References
- https://git.kernel.org/stable/c/2c2218560b6e28a63ff7834ba26d09ff8efdee39
- https://git.kernel.org/stable/c/6655c409707ec8ce9ce0850ffe4fe02331fd4d9c
- https://git.kernel.org/stable/c/86ead176301109b78e1d14c0e9d0d9ff9723c769
- https://git.kernel.org/stable/c/aaca16e042527f7efe48b50799bc662f1a191ce1
- https://git.kernel.org/stable/c/e26db0d636e4c24a6b16683ea95cf5077c64d74b