-

CVE-2026-90250

bpf, cgroup: Fix storage null-ptr-deref after replacing prog

In the Linux kernel, the following vulnerability has been resolved:

bpf, cgroup: Fix storage null-ptr-deref after replacing prog

Syzkaller reported a storage null-ptr-deref issue after replacing prog.
This occurs in the following scenario:
1. prog A, an empty prog, is attached to a cgrp.
2. prog B uses BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE and calls the
   bpf_get_local_storage helper.
3. link_update is called to replace prog A with prog B.

The reason is that __cgroup_bpf_replace fails to alloc and assign the
required cgrp storage for the incoming replacement prog. Consequently,
the new prog inherits an uninit storage, leading to null-ptr-deref panic
when kick the new prog.

Fix this by rejecting a link update if new_prog's cgroup storage is
incompatible with link->prog.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < a033c950f6731be88a7da98604ed78f302f15b80
Status affected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < 1ab3da12061d7ccb099f7e925fa2d865967a316a
Status affected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < 12feca126831556dc7fabe5a3ba28fbd328768b6
Status affected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < 3f562c537e9ecf4bc5e206cfffc2cc047f1b7e94
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a033c950f6731be88a7da98604ed78f302f15b80
https://git.kernel.org/stable/c/1ab3da12061d7ccb099f7e925fa2d865967a316a
https://git.kernel.org/stable/c/12feca126831556dc7fabe5a3ba28fbd328768b6
https://git.kernel.org/stable/c/3f562c537e9ecf4bc5e206cfffc2cc047f1b7e94