{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90312","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.801Z","datePublished":"2026-09-17T16:08:32.287Z","dateUpdated":"2026-09-18T17:54:29.867Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:29.867Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check load-acquire src ptr type before the load\n\ncheck_atomic_load() calls check_load_mem() before atomic_ptr_type_ok().\nFor a load-acquire that fetches into its own source register (dst_reg ==\nsrc_reg), check_load_mem() overwrites src_reg's type with the type of the\nloaded value, so the subsequent atomic_ptr_type_ok() no longer sees the\nsource pointer and fails to reject the disallowed types (ctx, pkt,\nflow_keys, sock).\n\nSince bpf_convert_ctx_accesses() does not rewrite atomic loads, the raw\naccess to the underlying kernel object is left in place. The destination\ntype is taken from the ctx access itself, so a load-acquire of the sk\nfield of struct __sk_buff for example leaves the register typed as\nPTR_TO_SOCK_COMMON_OR_NULL, which type_is_sk_pointer() does not match\neither, while it actually holds unconverted struct sk_buff bytes. Once\nthe NULL check has passed this is a type confusion, not just a leak of\nkernel data.\n\nValidate src_reg with check_reg_arg() and check the source pointer type\nwith atomic_ptr_type_ok() before the load again, mirroring\ncheck_atomic_rmw(). Out-of-range register numbers are already rejected\nearlier by check_and_resolve_insns() (commit 503d21ef8eac (\"bpf: Do\nregister range validation early\")), and the only exemption there,\nis_stack_arg_ldx(), requires BPF_LDX | BPF_MEM | BPF_DW and thus never\nmatches a BPF_ATOMIC insn. atomic_ptr_type_ok() can therefore not\ndereference register state out of bounds, that is, the out-of-bounds\nread addressed by the Fixes commit below does not reappear (as proven\nalso via selftest)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is a BPF_LOAD_ACQ insn with dst_reg==src_reg in the bytecode bpf_prog_load() copies from bpf(2) BPF_PROG_LOAD (__sys_bpf). do_check_insn()→check_atomic()→check_atomic_load() then lets check_load_mem() overwrite the source type before atomic_ptr_type_ok(); no remote protocol message carries that insn.\nAC:L - The attacker authors a SOCKET_FILTER program that does BPF_LOAD_ACQ of offsetof(__sk_buff, sk) with dst_reg==src_reg (the PTR_TO_CTX). check_load_mem() replaces that register with PTR_TO_SOCK_COMMON_OR_NULL, so type_is_sk_pointer() does not match and atomic_ptr_type_ok() accepts it. No race or uninfluenced layout is required.\nPR:L - bpf_prog_load() allows BPF_PROG_TYPE_SOCKET_FILTER and BPF_PROG_TYPE_CGROUP_SKB without CAP_BPF when sysctl_unprivileged_bpf_disabled is 0; otherwise bpf_token_capable(CAP_BPF) is enough. bpf_token_capable() uses ns_capable() on a delegated token userns, not init-namespace root. verifier_load_acquire.c marks socket load-acquire __success_unpriv.\nUI:N - The attacker loads the program with BPF_PROG_LOAD and runs it via BPF_PROG_TEST_RUN (bpf_prog_test_run_skb on sk_filter_prog_ops) or attaches it to their own socket with setsockopt(SO_ATTACH_BPF)→sk_attach_bpf() and triggers the filter. No other user must mount or open a file.\nS:U - check_atomic_load()'s type confusion and the later interpreter/JIT smp_load_acquire plus bpf_sock_convert_ctx_access loads run in the host kernel that accepted the program. That is in-kernel privilege escalation, not a KVM/Xen guest-to-host escape or IOMMU bypass.\nC:H - bpf_convert_ctx_accesses() does not rewrite BPF_ATOMIC, so load-acquire of offsetof(__sk_buff, sk) reads unconverted sk_buff bytes while the register is typed PTR_TO_SOCK_COMMON_OR_NULL. After a NULL check, later LDX of bpf_sock fields is rewritten by bpf_sock_convert_ctx_access() into struct sock loads against that pointer.\nI:H - The same confused PTR_TO_SOCK_COMMON is accepted as ARG_PTR_TO_SOCK_COMMON by bpf_sk_fullsock and, on CGROUP_SKB, bpf_sk_storage_get, which dereference and update sock-shaped kernel state on an object that is actually raw sk_buff memory. Commit-described verifier type confusion, not a bounded scalar leak.\nA:H - Interpreter BPF_LOAD_ACQ does smp_load_acquire of the unconverted ctx address, and follow-on bpf_sock_convert_ctx_access LDXes dereference that value as struct sock. A non-pointer or unmapped value page-faults in kernel context; the attacker can repeat this via BPF_PROG_TEST_RUN or the attached filter."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9","lessThan":"6ee7b00888498cf387dd30729e18a05328b94709","status":"affected","versionType":"git"},{"version":"c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9","lessThan":"422a416041172af1ac610736d5f556d22b31b115","status":"affected","versionType":"git"},{"version":"c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9","lessThan":"b87803391baa7e0bef60549d8841f12e549ad057","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6ee7b00888498cf387dd30729e18a05328b94709"},{"url":"https://git.kernel.org/stable/c/422a416041172af1ac610736d5f556d22b31b115"},{"url":"https://git.kernel.org/stable/c/b87803391baa7e0bef60549d8841f12e549ad057"}],"title":"bpf: Check load-acquire src ptr type before the load","x_generator":{"engine":"bippy-1.2.0"}}}}