Incorrect Conversion between Numeric Types in Linux kernel - CVE-2026-90195
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect handling of signed kfunc arguments.
The vulnerability exists due to incorrect numeric conversion in the RV64 BPF JIT compiler when processing signed 1-byte and 2-byte kfunc arguments. A local user can invoke a kfunc with signed 1-byte or 2-byte arguments to cause incorrect handling of signed kfunc arguments.