{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90143","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.789Z","datePublished":"2026-09-17T16:06:39.775Z","dateUpdated":"2026-09-18T17:53:21.163Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:21.163Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: kcm: Hold RCU read lock while running BPF parser\n\nkcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which\nprevents CPU migration, but does not establish an RCU read-side\ncritical section. Consequently, BPF map operations can trigger\nWARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser\nprogram.\n\nHold the RCU read lock while running the program."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The missing rcu_read_lock is in kcm_parse_func_strparser(), reached after local socket(AF_KCM) and ioctl(SIOCKCMATTACH) installing the caller's BPF_PROG_TYPE_SOCKET_FILTER via bpf_prog_get_type(). A remote TCP peer can only feed an skb into strp_recv(); map helpers fire regardless of payload, and the BPF program is locally supplied.\nAC:L - kcm_attach() always calls strp_check_rcv(), which queues do_strp_work so parse_msg runs in process context under lock_sock() with BH enabled, so bpf_rcu_lock_held() is false. The attacker loads a SOCKET_FILTER that calls bpf_map_lookup_elem and can delete the same HASH key from their own map fd on another thread.\nPR:L - kcm_create() and kcm_ioctl(SIOCKCMATTACH) have no capable() check, and PF_KCM autoloads via MODULE_ALIAS_NETPROTO. bpf_prog_get_type(..., BPF_PROG_TYPE_SOCKET_FILTER) and HASH/ARRAY maps are the unprivileged types in bpf_prog_load()/map_create(); CAP_BPF in the init namespace is not required when unprivileged BPF is enabled.\nUI:N - The attacker opens their own AF_KCM and TCP sockets, loads their own SOCKET_FILTER, issues SIOCKCMATTACH, and either pre-queues TCP data so strp_check_rcv() runs the parser or writes the TCP peer themselves. No other user must mount a filesystem, open a device, or attach a program.\nS:U - A dangling htab_elem used by kcm_parse_func_strparser() is a host-kernel use-after-free that can escalate privileges inside the same kernel. It does not cross a KVM/Xen guest-host boundary or an IOMMU/DMA domain.\nC:H - bpf_map_lookup_elem() proceeds after WARN_ON_ONCE(!bpf_rcu_lock_held()) and __htab_map_lookup_elem() still returns a pointer. Concurrent htab delete via the attacker's map fd frees or freelist-reuses that htab_elem (bpf_mem_cache_free/pcpu_freelist_push) while the SOCKET_FILTER still reads the map value, disclosing kernel heap.\nI:H - The verifier treats the map-value pointer as writable, so the SOCKET_FILTER can store through the dangling htab_elem after free_htab_elem() reuses it, and bpf_map_update_elem() also runs without RCU from kcm_parse_func_strparser(). That is an arbitrary kernel write via heap reuse, not a bounded overwrite.\nA:H - Use of the dangling htab_elem in do_strp_work oopses or panics the kernel. Independently, bpf_map_lookup_elem()/__htab_map_lookup_elem() hit WARN_ON_ONCE(!bpf_rcu_lock_held()) on the first map helper from kcm_parse_func_strparser(), which is fatal on kernels booted with panic_on_warn."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/kcm/kcmsock.c"],"versions":[{"version":"9b73896a81dc68a638a011877b7344b252f92276","lessThan":"37108861cf7bd909d4a372069bcd61c8f489e232","status":"affected","versionType":"git"},{"version":"9b73896a81dc68a638a011877b7344b252f92276","lessThan":"3c70d27e792a28bca650ddd8a9aa0fe3591ffec5","status":"affected","versionType":"git"},{"version":"9b73896a81dc68a638a011877b7344b252f92276","lessThan":"1d26a6e007d46babc7fa76e5a157dccf86cd55c0","status":"affected","versionType":"git"},{"version":"9b73896a81dc68a638a011877b7344b252f92276","lessThan":"b0e94ea63dbdcbfec9beb819cd5f8fa584809ef2","status":"affected","versionType":"git"},{"version":"9b73896a81dc68a638a011877b7344b252f92276","lessThan":"21526f8a191a3c50622b8c10bd927870d780eae4","status":"affected","versionType":"git"},{"version":"9b73896a81dc68a638a011877b7344b252f92276","lessThan":"292846223eaddba890e40699d2ab82ee5671798c","status":"affected","versionType":"git"},{"version":"9b73896a81dc68a638a011877b7344b252f92276","lessThan":"f392affef3c9ce64dfdde794df0579e0a7793440","status":"affected","versionType":"git"},{"version":"9b73896a81dc68a638a011877b7344b252f92276","lessThan":"b0346dd64e4905291cc9c479f2e6cf1884ced4e6","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/kcm/kcmsock.c"],"versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/37108861cf7bd909d4a372069bcd61c8f489e232"},{"url":"https://git.kernel.org/stable/c/3c70d27e792a28bca650ddd8a9aa0fe3591ffec5"},{"url":"https://git.kernel.org/stable/c/1d26a6e007d46babc7fa76e5a157dccf86cd55c0"},{"url":"https://git.kernel.org/stable/c/b0e94ea63dbdcbfec9beb819cd5f8fa584809ef2"},{"url":"https://git.kernel.org/stable/c/21526f8a191a3c50622b8c10bd927870d780eae4"},{"url":"https://git.kernel.org/stable/c/292846223eaddba890e40699d2ab82ee5671798c"},{"url":"https://git.kernel.org/stable/c/f392affef3c9ce64dfdde794df0579e0a7793440"},{"url":"https://git.kernel.org/stable/c/b0346dd64e4905291cc9c479f2e6cf1884ced4e6"}],"title":"net: kcm: Hold RCU read lock while running BPF parser","x_generator":{"engine":"bippy-1.2.0"}}}}