Use of insufficiently random values in Linux kernel - CVE-2026-90110
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass IP-keyed ICMP rate limits and infer open UDP ports.
The vulnerability exists due to predictable tree ordering in the inetpeer rate limiting system when processing packets from remote IP addresses. A remote attacker can trigger garbage collection and selectively evict inet_peer entries to bypass IP-keyed ICMP rate limits and infer open UDP ports.
Re-created entries have their rate-limiting token buckets reset to full capacity.
Affected software
How to mitigate CVE-2026-90110
External References
- https://git.kernel.org/stable/c/199fcf285e498111e029137d088949bc6c26d578
- https://git.kernel.org/stable/c/2ee66e9487172fcd189bc52a767c30dad7141c09
- https://git.kernel.org/stable/c/5f127e3cc9647a8a70db12c65dbd0de473545380
- https://git.kernel.org/stable/c/7109bb63667a53e4542ad845476f97d0c8b28a61
- https://git.kernel.org/stable/c/857681f6835d5b0a7bc4a34a026baeaaf5215623
- https://git.kernel.org/stable/c/b20e98f0bb668a59abaf7bcf85d75c073e90d352