NULL pointer dereference in Linux kernel - CVE-2026-90250
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the cgroup BPF program replacement logic when replacing an attached cgroup BPF program through link_update. A local user can replace an empty attached program with a program that uses per-CPU cgroup storage to cause a denial of service.