Use-after-free in Linux kernel - CVE-2026-90317
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to access a freed task_struct object.
The vulnerability exists due to improper handling of RCU-protected pointers in the BPF verifier when releasing the final BPF spin lock in a sleepable BPF program and subsequently using an RCU-protected kptr. A local user can execute a BPF program that uses an RCU-protected kptr after releasing its final spin lock to access a freed task_struct object.
The pointer remains valid to the verifier after the final lock release, allowing another CPU to free the referenced object before it is used.