7.8

CVE-2026-90392

bpf: Fix potential UAF when reading bpf link info

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix potential UAF when reading bpf link info

In bpf_link_show_fdinfo and bpf_link_get_info_by_fd, link->prog is
accessed without holding any locks. If the prog is concurrently replaced
via bpf_link_update, the old prog can be freed, leading to a potential
UAF issue.

Fix this by accessing link->prog under RCU protection to safely fetch
the pointer and guarantee its lifetime while reading its fields.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < a5c936ac904767fc1d943d40b0308bcb2ae2509b
Status affected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < d7d7208e2603b45724b684f4df73904fb347741e
Status affected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < 85cf991c881e7198be32be05a9daa2625390c8b3
Status affected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < 79347e42cfbc9e78872922e8f08a70609c9af82f
Status affected
Version 0c991ebc8c69d29b7fc44db17075c5aa5253e2ab
Version < 863f3ddd0b8ac65abfb50d3be0869268ac0e277b
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a5c936ac904767fc1d943d40b0308bcb2ae2509b
https://git.kernel.org/stable/c/d7d7208e2603b45724b684f4df73904fb347741e
https://git.kernel.org/stable/c/85cf991c881e7198be32be05a9daa2625390c8b3
https://git.kernel.org/stable/c/79347e42cfbc9e78872922e8f08a70609c9af82f
https://git.kernel.org/stable/c/863f3ddd0b8ac65abfb50d3be0869268ac0e277b