-

CVE-2026-90313

bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed

In the Linux kernel, the following vulnerability has been resolved:

bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed

A potential invalid storage access issue can occur after replacing a
cgroup bpf prog.

This occurs in the following scenario:
1. prog1 with storage is attached to a cgroup in multi-attach mode.
2. prog1 is replaced with prog2 using BPF_F_REPLACE in multi-attach
   mode, but fails midway (e.g. in bpf_trampoline_link_cgroup_shim or
   update_effective_progs).
3. A new prog3 is attached to the cgroup in multi-attach mode.

The reason is that __cgroup_bpf_attach overwrites pl->storage with the
new storage prior to attachment completion. When attachment fails
midway, the cleanup path calls bpf_cgroup_storages_free(new_storage) to
free the newly allocated storage, but fails to restore pl->storage back
to old_storage.

Consequently, the still-active prog1 holds invalid or dangling storage
pointers, leading to an invalid memory access when prog1 executes and
calls bpf_get_local_storage. Additionally, original pl->flags and
cgrp->bpf.flags[atype] are left unrestored.

Fix this by saving old_pl_flags, old_storage, and old_flags prior to the
update, and properly restoring all of them in the cleanup path on error.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7d9c3427894fe70d1347b4820476bf37736d2ff0
Version < e26db0d636e4c24a6b16683ea95cf5077c64d74b
Status affected
Version 7d9c3427894fe70d1347b4820476bf37736d2ff0
Version < aaca16e042527f7efe48b50799bc662f1a191ce1
Status affected
Version 7d9c3427894fe70d1347b4820476bf37736d2ff0
Version < 86ead176301109b78e1d14c0e9d0d9ff9723c769
Status affected
Version 7d9c3427894fe70d1347b4820476bf37736d2ff0
Version < 2c2218560b6e28a63ff7834ba26d09ff8efdee39
Status affected
Version 7d9c3427894fe70d1347b4820476bf37736d2ff0
Version < 6655c409707ec8ce9ce0850ffe4fe02331fd4d9c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.9
Status affected
Version 0
Version < 5.9
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e26db0d636e4c24a6b16683ea95cf5077c64d74b
https://git.kernel.org/stable/c/aaca16e042527f7efe48b50799bc662f1a191ce1
https://git.kernel.org/stable/c/86ead176301109b78e1d14c0e9d0d9ff9723c769
https://git.kernel.org/stable/c/2c2218560b6e28a63ff7834ba26d09ff8efdee39
https://git.kernel.org/stable/c/6655c409707ec8ce9ce0850ffe4fe02331fd4d9c