{"api_version":"1","generated_at":"2026-10-01T12:24:04+00:00","cve":"CVE-2026-90110","urls":{"html":"https://cve.report/CVE-2026-90110","api":"https://cve.report/api/cve/CVE-2026-90110.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90110","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90110"},"summary":{"title":"inetpeer: randomize RB-tree node comparison using SipHash","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ninetpeer: randomize RB-tree node comparison using SipHash\n\nThe inetpeer rate limiting system stores peer entries in a Red-Black tree\nkeyed deterministically on the remote IP address. Because tree lookups walk\nthe RB-tree using standard lexicographical comparisons (inetpeer_addr_cmp),\nan off-path adversary can predict the exact topology of the tree and the\nsequence of nodes traversed during lookups (the gc_stack candidate list).\n\nBy combining deterministic tree traversal with aggressive garbage collection\n(triggered when tree size exceeds inet_peer_threshold), an attacker can\nselectively force the eviction of targeted inet_peer nodes. When an evicted\nnode is subsequently re-created upon receiving a new packet, its rate-limiting\ntoken bucket (rate_tokens, rate_last) is reset to full capacity. This creates\na side-channel primitive allowing off-path attackers to bypass IP-keyed ICMP\nrate limits and infer open UDP ports (similar to SAD DNS style attacks).\n\nMitigate this by randomizing the RB-tree node comparison logic using SipHash\nwith a secret key (inetpeer_hash_key) initialized via net_get_random_once().\nNodes are ordered in the tree by SipHash(addr, key) rather than raw IP\naddresses. Because the secret key is unknown to external entities, the tree\nlayout and lookup traversal paths are unpredictable to off-path adversaries,\nbreaking the deterministic eviction gadget.\n\nCache the computed 64-bit SipHash (hash) in struct inet_peer and compute the\ntarget hash (dhash) once at the beginning of inet_getpeer() to avoid recomputing\nSipHash at every step of the RB-tree walk.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:02","updated_at":"2026-09-18 18:17:42"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.4","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.4","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","data":{"baseScore":9.4,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/5f127e3cc9647a8a70db12c65dbd0de473545380","name":"https://git.kernel.org/stable/c/5f127e3cc9647a8a70db12c65dbd0de473545380","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2ee66e9487172fcd189bc52a767c30dad7141c09","name":"https://git.kernel.org/stable/c/2ee66e9487172fcd189bc52a767c30dad7141c09","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7109bb63667a53e4542ad845476f97d0c8b28a61","name":"https://git.kernel.org/stable/c/7109bb63667a53e4542ad845476f97d0c8b28a61","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/199fcf285e498111e029137d088949bc6c26d578","name":"https://git.kernel.org/stable/c/199fcf285e498111e029137d088949bc6c26d578","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/857681f6835d5b0a7bc4a34a026baeaaf5215623","name":"https://git.kernel.org/stable/c/857681f6835d5b0a7bc4a34a026baeaaf5215623","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b20e98f0bb668a59abaf7bcf85d75c073e90d352","name":"https://git.kernel.org/stable/c/b20e98f0bb668a59abaf7bcf85d75c073e90d352","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90110","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90110","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b145425f269a17ed344d737f746b844dfac60c82 b20e98f0bb668a59abaf7bcf85d75c073e90d352 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b145425f269a17ed344d737f746b844dfac60c82 5f127e3cc9647a8a70db12c65dbd0de473545380 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b145425f269a17ed344d737f746b844dfac60c82 199fcf285e498111e029137d088949bc6c26d578 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b145425f269a17ed344d737f746b844dfac60c82 857681f6835d5b0a7bc4a34a026baeaaf5215623 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b145425f269a17ed344d737f746b844dfac60c82 7109bb63667a53e4542ad845476f97d0c8b28a61 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b145425f269a17ed344d737f746b844dfac60c82 2ee66e9487172fcd189bc52a767c30dad7141c09 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.14","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.14 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90110","cve":"CVE-2026-90110","epss":"0.005950000","percentile":"0.468370000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["include/net/inetpeer.h","net/ipv4/inetpeer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"b20e98f0bb668a59abaf7bcf85d75c073e90d352","status":"affected","version":"b145425f269a17ed344d737f746b844dfac60c82","versionType":"git"},{"lessThan":"5f127e3cc9647a8a70db12c65dbd0de473545380","status":"affected","version":"b145425f269a17ed344d737f746b844dfac60c82","versionType":"git"},{"lessThan":"199fcf285e498111e029137d088949bc6c26d578","status":"affected","version":"b145425f269a17ed344d737f746b844dfac60c82","versionType":"git"},{"lessThan":"857681f6835d5b0a7bc4a34a026baeaaf5215623","status":"affected","version":"b145425f269a17ed344d737f746b844dfac60c82","versionType":"git"},{"lessThan":"7109bb63667a53e4542ad845476f97d0c8b28a61","status":"affected","version":"b145425f269a17ed344d737f746b844dfac60c82","versionType":"git"},{"lessThan":"2ee66e9487172fcd189bc52a767c30dad7141c09","status":"affected","version":"b145425f269a17ed344d737f746b844dfac60c82","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["include/net/inetpeer.h","net/ipv4/inetpeer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.14"},{"lessThan":"4.14","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"4.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"4.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"4.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"4.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"4.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"4.14","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ninetpeer: randomize RB-tree node comparison using SipHash\n\nThe inetpeer rate limiting system stores peer entries in a Red-Black tree\nkeyed deterministically on the remote IP address. Because tree lookups walk\nthe RB-tree using standard lexicographical comparisons (inetpeer_addr_cmp),\nan off-path adversary can predict the exact topology of the tree and the\nsequence of nodes traversed during lookups (the gc_stack candidate list).\n\nBy combining deterministic tree traversal with aggressive garbage collection\n(triggered when tree size exceeds inet_peer_threshold), an attacker can\nselectively force the eviction of targeted inet_peer nodes. When an evicted\nnode is subsequently re-created upon receiving a new packet, its rate-limiting\ntoken bucket (rate_tokens, rate_last) is reset to full capacity. This creates\na side-channel primitive allowing off-path attackers to bypass IP-keyed ICMP\nrate limits and infer open UDP ports (similar to SAD DNS style attacks).\n\nMitigate this by randomizing the RB-tree node comparison logic using SipHash\nwith a secret key (inetpeer_hash_key) initialized via net_get_random_once().\nNodes are ordered in the tree by SipHash(addr, key) rather than raw IP\naddresses. Because the secret key is unknown to external entities, the tree\nlayout and lookup traversal paths are unpredictable to off-path adversaries,\nbreaking the deterministic eviction gadget.\n\nCache the computed 64-bit SipHash (hash) in struct inet_peer and compute the\ntarget hash (dhash) once at the beginning of inet_getpeer() to avoid recomputing\nSipHash at every step of the RB-tree walk."}],"metrics":[{"cvssV3_1":{"baseScore":9.4,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - A received IPv4 UDP datagram to a closed port takes ip_rcv → ip_local_deliver → udp_rcv() → icmp_send() → icmpv4_xrlim_allow() → inet_getpeer_v4(), with icmp_route_lookup() setting fl4->daddr from iph->saddr; ip4_frag_init() also keys inet_getpeer_v4() on the fragment source. Those attacker-chosen addresses are the inetpeer RB-tree keys on a routable IP path.\nAC:L - The attacker chooses the source addresses inetpeer_addr_cmp() orders, grows base->total past inet_peer_threshold via inet_getpeer() on those UDP/ICMP or fragment lookups, then looks up further keys so lookup() pushes the victim inet_peer onto gc_stack and inet_peer_gc() evicts it (ttl=0, refcount_dec_if_one). Tree shape and eviction set are functions of those keys, not uninfluenced victim state.\nPR:N - udp_rcv() emits ICMP_PORT_UNREACH and icmpv4_xrlim_allow() calls inet_getpeer_v4() for any inbound IPv4/UDP packet with no socket, credential, or capability check; ip4_frag_init() likewise creates peers from unauthenticated fragment sources.\nUI:N - Peer insertion in inet_getpeer(), gc_stack collection in lookup(), and the rate_tokens/rate_last reset when a GC'd inet_peer is kmem_cache_alloc'd again all run in the receive/softirq path of the attacker's own packets; no local user must mount, open, or otherwise act.\nS:U - The inet_peer RB-tree and ICMP token bucket live in the host IPv4/IPv6 stack; any recovered UDP port or poisoned resolver cache remains that host's network-stack authority, with no VM, IOMMU, or sandbox boundary crossed.\nC:H - Evicting a chosen node via lookup()'s gc_stack and recreating it in inet_getpeer() sets rate_tokens=0 and rate_last=jiffies-60*HZ so inet_peer_xrlim_allow() starts at full burst, resetting the per-IP ICMP oracle and letting an off-path attacker infer open/ephemeral UDP ports (SAD DNS), defeating source-port randomization.\nI:H - Recovering the ephemeral UDP source port of an in-flight DNS query through that reset inet_peer_xrlim_allow() oracle lets the same off-path attacker spoof the nameserver reply, win the race against the legitimate response, and poison the resolver cache, arbitrarily redirecting later lookups.\nA:L - Repeated inet_peer_gc() eviction and inet_getpeer() recreate of rate_tokens lets the attacker keep passing inet_peer_xrlim_allow() and drain icmp_global_credit, suppressing ICMP errors (port unreachable, time exceeded) to other peers; lookup() and inet_peer_gc() do not oops, so the loss is ICMP signalling degradation rather than a crash."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:53:04.902Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/b20e98f0bb668a59abaf7bcf85d75c073e90d352"},{"url":"https://git.kernel.org/stable/c/5f127e3cc9647a8a70db12c65dbd0de473545380"},{"url":"https://git.kernel.org/stable/c/199fcf285e498111e029137d088949bc6c26d578"},{"url":"https://git.kernel.org/stable/c/857681f6835d5b0a7bc4a34a026baeaaf5215623"},{"url":"https://git.kernel.org/stable/c/7109bb63667a53e4542ad845476f97d0c8b28a61"},{"url":"https://git.kernel.org/stable/c/2ee66e9487172fcd189bc52a767c30dad7141c09"}],"title":"inetpeer: randomize RB-tree node comparison using SipHash","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90110","datePublished":"2026-09-17T16:06:18.113Z","dateReserved":"2026-09-11T19:38:34.787Z","dateUpdated":"2026-09-18T17:53:04.902Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:02","lastModifiedDate":"2026-09-18 18:17:42","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.5}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90110","Ordinal":"1","Title":"inetpeer: randomize RB-tree node comparison using SipHash","CVE":"CVE-2026-90110","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90110","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ninetpeer: randomize RB-tree node comparison using SipHash\n\nThe inetpeer rate limiting system stores peer entries in a Red-Black tree\nkeyed deterministically on the remote IP address. Because tree lookups walk\nthe RB-tree using standard lexicographical comparisons (inetpeer_addr_cmp),\nan off-path adversary can predict the exact topology of the tree and the\nsequence of nodes traversed during lookups (the gc_stack candidate list).\n\nBy combining deterministic tree traversal with aggressive garbage collection\n(triggered when tree size exceeds inet_peer_threshold), an attacker can\nselectively force the eviction of targeted inet_peer nodes. When an evicted\nnode is subsequently re-created upon receiving a new packet, its rate-limiting\ntoken bucket (rate_tokens, rate_last) is reset to full capacity. This creates\na side-channel primitive allowing off-path attackers to bypass IP-keyed ICMP\nrate limits and infer open UDP ports (similar to SAD DNS style attacks).\n\nMitigate this by randomizing the RB-tree node comparison logic using SipHash\nwith a secret key (inetpeer_hash_key) initialized via net_get_random_once().\nNodes are ordered in the tree by SipHash(addr, key) rather than raw IP\naddresses. Because the secret key is unknown to external entities, the tree\nlayout and lookup traversal paths are unpredictable to off-path adversaries,\nbreaking the deterministic eviction gadget.\n\nCache the computed 64-bit SipHash (hash) in struct inet_peer and compute the\ntarget hash (dhash) once at the beginning of inet_getpeer() to avoid recomputing\nSipHash at every step of the RB-tree walk.","Type":"Description","Title":"inetpeer: randomize RB-tree node comparison using SipHash"}]}}}