Off-by-one in Linux kernel - CVE-2026-90160
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to an off-by-one headroom validation error in the lwt_bpf bpf_xmit() path when an LWT_XMIT BPF program modifies skb headroom. A local privileged user can call bpf_skb_change_head() to leave insufficient headroom and cause a denial of service.
On Ethernet, cached hardware-header output requires 16 bytes of headroom although the device hard-header length is 14 bytes.
Affected software
How to mitigate CVE-2026-90160
External References
- https://git.kernel.org/stable/c/179a5b2171573d94a25c9aa8e1c9f9ac352ad316
- https://git.kernel.org/stable/c/5fe7007aed9ad069b2bd77e5d0c875c64f5c0269
- https://git.kernel.org/stable/c/753e5cdcca5474d230d62bb3489e5168ab27c272
- https://git.kernel.org/stable/c/7cf561843ed0ad57501892a65abb77957e6c800f
- https://git.kernel.org/stable/c/7d043e24520a273c362be5dd7d9c82796879a49b
- https://git.kernel.org/stable/c/a38c0eb447e2dd0120a2ebcdba470f9505ac8907
- https://git.kernel.org/stable/c/c488071c3441fa34f5a87cd6c12ce2cc6304f20e
- https://git.kernel.org/stable/c/de2b2004e16f2930eb689175e2c1998b0a68d499