{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90177","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.791Z","datePublished":"2026-09-17T16:07:03.097Z","dateUpdated":"2026-09-18T17:53:37.480Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:37.480Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check pointer type for all atomic RMW paths\n\nAtomic RMW verification records an instruction pointer type only when the\ncurrent destination is PTR_TO_ARENA. A second path can therefore reach the\nsame instruction with an ordinary pointer without comparing it against the\nsaved arena type.\n\nThe post-verification fixup uses the saved type to rewrite the instruction\nto BPF_PROBE_ATOMIC for every path. Record the actual destination type for\nall atomic RMW paths so the existing mismatch check rejects incompatible\nuses of one instruction."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is the BPF instruction stream copied in bpf_prog_load() from bpf(2) BPF_PROG_LOAD (__sys_bpf). do_check_insn() then check_atomic() then check_atomic_rmw() sees a mixed PTR_TO_ARENA versus kernel-pointer atomic; that bytecode is local syscall input, not a remote protocol payload.\nAC:L - The attacker authors both verifier paths: one branch with a PTR_TO_ARENA destination and another with PTR_TO_MAP_VALUE or PTR_TO_STACK at the same BPF_ATOMIC RMW. check_atomic_rmw() records only the arena type, bpf_convert_ctx_accesses() rewrites it to BPF_PROBE_ATOMIC, and bpf_prog_test_run_syscall() takes the non-arena path on demand.\nPR:L - The mixed path needs a BPF_MAP_TYPE_ARENA map; check_map_prog_compatibility() rejects that unless env->bpf_capable and env->allow_ptr_leaks (bpf_token_capable(CAP_BPF) and bpf_token_capable(CAP_PERFMON)). bpf_token_capable() uses ns_capable() on a delegated token userns, so this is not init-namespace root.\nUI:N - The attacker creates the arena with BPF_MAP_CREATE, loads the mixed-path program with BPF_PROG_LOAD, and executes it via bpf_prog_test_run() to bpf_prog_test_run_syscall(); no other user must mount, open a file, or otherwise cooperate.\nS:U - The confused BPF_PROBE_ATOMIC is JITed as emit_atomic_rmw_index() adding arena kern_vm_start (R12) onto a kernel map or stack pointer and runs in the host kernel; that is host memory corruption, not a KVM/Xen guest-to-host escape or IOMMU bypass.\nC:H - After bpf_convert_ctx_accesses() rewrites the shared RMW to BPF_PROBE_ATOMIC, the non-arena path executes lock xchg/cmpxchg/fetch-add at (PTR_TO_MAP_VALUE or PTR_TO_STACK + bpf_arena_get_kern_vm_start()). BPF_FETCH, XCHG, and CMPXCHG return the old value from that address, an arbitrary kernel read.\nI:H - The same instruction performs an attacker-chosen atomic RMW (BPF_ADD/AND/OR/XOR/XCHG/CMPXCHG in check_atomic_rmw) at kernel_ptr+kern_vm_start. With CONFIG_VMAP_STACK or a vmalloc map, that sum is a canonical direct-map address, giving a kernel write primitive.\nA:H - An atomic RMW into the direct map corrupts live kernel state and can panic; a non-canonical or unmapped sum that a JIT does not cover with an exception table oopses. Type-confused kernel atomics are Availability High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"d503a04f8bc0c75dc9db9452d8cc79d748afb752","lessThan":"eb287c6e81dedef92da01eb947f380d0aae513c3","status":"affected","versionType":"git"},{"version":"d503a04f8bc0c75dc9db9452d8cc79d748afb752","lessThan":"4bc49ae344d65cfcef738f281ac575cf73ca2fc5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/eb287c6e81dedef92da01eb947f380d0aae513c3"},{"url":"https://git.kernel.org/stable/c/4bc49ae344d65cfcef738f281ac575cf73ca2fc5"}],"title":"bpf: Check pointer type for all atomic RMW paths","x_generator":{"engine":"bippy-1.2.0"}}}}