Use-after-free in Linux kernel - CVE-2026-90317

 

Use-after-free in Linux kernel - CVE-2026-90317

Published: September 18, 2026


Vulnerability identifier: #VU151168
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90317
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to access a freed task_struct object.

The vulnerability exists due to improper handling of RCU-protected pointers in the BPF verifier when releasing the final BPF spin lock in a sleepable BPF program and subsequently using an RCU-protected kptr. A local user can execute a BPF program that uses an RCU-protected kptr after releasing its final spin lock to access a freed task_struct object.

The pointer remains valid to the verifier after the final lock release, allowing another CPU to free the referenced object before it is used.


Affected software

Linux kernel

How to mitigate CVE-2026-90317

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins