Improper input validation in Linux kernel - CVE-2026-90146
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to bypass XDP program attachment restrictions.
The vulnerability exists due to improper input validation in XDP link update handling when replacing an XDP program through BPF_LINK_UPDATE. A local user can create an XDP link with a normal program and replace it with an offloaded or device-bound program to bypass XDP program attachment restrictions.