{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90146","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.789Z","datePublished":"2026-09-17T16:06:41.695Z","dateUpdated":"2026-09-18T17:53:23.835Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:23.835Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, xdp: move offload check into dev_xdp_install()\n\nbpf_xdp_link_update() calls dev_xdp_install() directly and skips\ndev_xdp_attach(), so the checks in dev_xdp_attach() do not run. A user can\nmake an XDP link with a normal program and then swap in an offloaded or\ndevice-bound program with BPF_LINK_UPDATE, which puts it on the software\npath.\n\ndev_xdp_install() is the one place all three paths go through:\n\"ip link set xdp\" and BPF_LINK_CREATE reach it via dev_xdp_attach(), and\nBPF_LINK_UPDATE calls it directly. So move the program checks (offloaded,\nbound to another device, device-bound in generic mode, native vs generic,\nDEVMAP and CPUMAP) there, and keep only the netlink-flag check\n(XDP_FLAGS_UPDATE_IF_NOEXIST) in dev_xdp_attach()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled data is the replacement program fd on bpf(BPF_LINK_UPDATE), which __sys_bpf() dispatches to link_update() then bpf_xdp_link_update() in net/core/dev.c; that local syscall installs the prog, rather than a parsed ksmbd/nfsd/packet payload.\nAC:L - bpf_xdp_link_update() only compares prog->type and expected_attach_type, so BPF_LINK_CREATE of a normal XDP prog on a veth with XDP_FLAGS_SKB_MODE followed by BPF_LINK_UPDATE of a BPF_F_XDP_DEV_BOUND_ONLY prog that calls bpf_xdp_metadata_rx_* always bypasses the skipped dev_xdp_attach() checks, with no race.\nPR:L - bpf_prog_load() of BPF_PROG_TYPE_XDP requires bpf_token_capable(CAP_BPF) and bpf_token_capable(CAP_NET_ADMIN) before bpf_xdp_link_attach()/link_update(); those caps, and the CAP_NET_ADMIN to add the veth attach target, are obtainable in a user/netns via unshare and BPF token delegation, not only init-namespace root.\nUI:N - The attacker loads both programs, creates the XDP link, calls BPF_LINK_UPDATE, and then drives do_xdp_generic() by sending a frame through their own veth peer; no victim mount, file open, or other cooperative action is required.\nS:U - The confused metadata kfuncs (veth_xdp_rx_hash() and friends) run in the host kernel XDP path do_xdp_generic()/bpf_prog_run_generic_xdp() and corrupt host kernel memory; this is not a KVM/Xen guest-to-host escape or an IOMMU/DMA boundary bypass.\nC:H - After the skipped bpf_prog_is_dev_bound() checks, a veth-bound program can run on generic XDP's stack struct xdp_buff; veth_xdp_rx_timestamp()/veth_xdp_rx_vlan_tag() cast it to veth_xdp_buff and read skb_hwtstamps()/vlan fields through that bogus skb pointer, an unbounded kernel read into BPF maps.\nI:H - The same confused veth_xdp_buff.skb is passed to skb_get_hash(), which writes hash/sw_hash/l4_hash via __skb_get_hash_net(); swapping a veth-bound prog onto mlx5 native XDP likewise treats mlx5e_xdp_buff.cqe as an sk_buff and writes into the CQE, which is type confusion with a kernel write.\nA:H - do_xdp_generic() allocates a bare struct xdp_buff, so the next RX after the bad BPF_LINK_UPDATE makes veth_xdp_rx_hash() or mlx5e_xdp_rx_timestamp() dereference adjacent stack/wrapper bytes as skb, cqe, or rq and oops; an offloaded prog swapped onto the software path also hits bpf_prog_warn_on_exec() per packet."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/dev.c"],"versions":[{"version":"026a4c28e1db3b0cb99cd9a3e495d4a8b632fa74","lessThan":"ea7b35dcc9430293b861bc7bad0c546f193c85f9","status":"affected","versionType":"git"},{"version":"026a4c28e1db3b0cb99cd9a3e495d4a8b632fa74","lessThan":"03022dd874070768a7099f18b1944c633641315f","status":"affected","versionType":"git"},{"version":"026a4c28e1db3b0cb99cd9a3e495d4a8b632fa74","lessThan":"ad27ed7d2309419a129078d781504f486b1b469a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/dev.c"],"versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ea7b35dcc9430293b861bc7bad0c546f193c85f9"},{"url":"https://git.kernel.org/stable/c/03022dd874070768a7099f18b1944c633641315f"},{"url":"https://git.kernel.org/stable/c/ad27ed7d2309419a129078d781504f486b1b469a"}],"title":"bpf, xdp: move offload check into dev_xdp_install()","x_generator":{"engine":"bippy-1.2.0"}}}}