{"api_version":"1","generated_at":"2026-10-04T11:44:01+00:00","cve":"CVE-2026-90177","urls":{"html":"https://cve.report/CVE-2026-90177","api":"https://cve.report/api/cve/CVE-2026-90177.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90177","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90177"},"summary":{"title":"bpf: Check pointer type for all atomic RMW paths","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check pointer type for all atomic RMW paths\n\nAtomic RMW verification records an instruction pointer type only when the\ncurrent destination is PTR_TO_ARENA. A second path can therefore reach the\nsame instruction with an ordinary pointer without comparing it against the\nsaved arena type.\n\nThe post-verification fixup uses the saved type to rewrite the instruction\nto BPF_PROBE_ATOMIC for every path. Record the actual destination type for\nall atomic RMW paths so the existing mismatch check rejects incompatible\nuses of one instruction.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:11","updated_at":"2026-09-18 18:17:45"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/4bc49ae344d65cfcef738f281ac575cf73ca2fc5","name":"https://git.kernel.org/stable/c/4bc49ae344d65cfcef738f281ac575cf73ca2fc5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/eb287c6e81dedef92da01eb947f380d0aae513c3","name":"https://git.kernel.org/stable/c/eb287c6e81dedef92da01eb947f380d0aae513c3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90177","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90177","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d503a04f8bc0c75dc9db9452d8cc79d748afb752 eb287c6e81dedef92da01eb947f380d0aae513c3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d503a04f8bc0c75dc9db9452d8cc79d748afb752 4bc49ae344d65cfcef738f281ac575cf73ca2fc5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.10","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.10 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90177","cve":"CVE-2026-90177","epss":"0.001540000","percentile":"0.048960000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"eb287c6e81dedef92da01eb947f380d0aae513c3","status":"affected","version":"d503a04f8bc0c75dc9db9452d8cc79d748afb752","versionType":"git"},{"lessThan":"4bc49ae344d65cfcef738f281ac575cf73ca2fc5","status":"affected","version":"d503a04f8bc0c75dc9db9452d8cc79d748afb752","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.10"},{"lessThan":"6.10","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"6.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.10","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check pointer type for all atomic RMW paths\n\nAtomic RMW verification records an instruction pointer type only when the\ncurrent destination is PTR_TO_ARENA. A second path can therefore reach the\nsame instruction with an ordinary pointer without comparing it against the\nsaved arena type.\n\nThe post-verification fixup uses the saved type to rewrite the instruction\nto BPF_PROBE_ATOMIC for every path. Record the actual destination type for\nall atomic RMW paths so the existing mismatch check rejects incompatible\nuses of one instruction."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is the BPF instruction stream copied in bpf_prog_load() from bpf(2) BPF_PROG_LOAD (__sys_bpf). do_check_insn() then check_atomic() then check_atomic_rmw() sees a mixed PTR_TO_ARENA versus kernel-pointer atomic; that bytecode is local syscall input, not a remote protocol payload.\nAC:L - The attacker authors both verifier paths: one branch with a PTR_TO_ARENA destination and another with PTR_TO_MAP_VALUE or PTR_TO_STACK at the same BPF_ATOMIC RMW. check_atomic_rmw() records only the arena type, bpf_convert_ctx_accesses() rewrites it to BPF_PROBE_ATOMIC, and bpf_prog_test_run_syscall() takes the non-arena path on demand.\nPR:L - The mixed path needs a BPF_MAP_TYPE_ARENA map; check_map_prog_compatibility() rejects that unless env->bpf_capable and env->allow_ptr_leaks (bpf_token_capable(CAP_BPF) and bpf_token_capable(CAP_PERFMON)). bpf_token_capable() uses ns_capable() on a delegated token userns, so this is not init-namespace root.\nUI:N - The attacker creates the arena with BPF_MAP_CREATE, loads the mixed-path program with BPF_PROG_LOAD, and executes it via bpf_prog_test_run() to bpf_prog_test_run_syscall(); no other user must mount, open a file, or otherwise cooperate.\nS:U - The confused BPF_PROBE_ATOMIC is JITed as emit_atomic_rmw_index() adding arena kern_vm_start (R12) onto a kernel map or stack pointer and runs in the host kernel; that is host memory corruption, not a KVM/Xen guest-to-host escape or IOMMU bypass.\nC:H - After bpf_convert_ctx_accesses() rewrites the shared RMW to BPF_PROBE_ATOMIC, the non-arena path executes lock xchg/cmpxchg/fetch-add at (PTR_TO_MAP_VALUE or PTR_TO_STACK + bpf_arena_get_kern_vm_start()). BPF_FETCH, XCHG, and CMPXCHG return the old value from that address, an arbitrary kernel read.\nI:H - The same instruction performs an attacker-chosen atomic RMW (BPF_ADD/AND/OR/XOR/XCHG/CMPXCHG in check_atomic_rmw) at kernel_ptr+kern_vm_start. With CONFIG_VMAP_STACK or a vmalloc map, that sum is a canonical direct-map address, giving a kernel write primitive.\nA:H - An atomic RMW into the direct map corrupts live kernel state and can panic; a non-canonical or unmapped sum that a JIT does not cover with an exception table oopses. Type-confused kernel atomics are Availability High."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:53:37.480Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/eb287c6e81dedef92da01eb947f380d0aae513c3"},{"url":"https://git.kernel.org/stable/c/4bc49ae344d65cfcef738f281ac575cf73ca2fc5"}],"title":"bpf: Check pointer type for all atomic RMW paths","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90177","datePublished":"2026-09-17T16:07:03.097Z","dateReserved":"2026-09-11T19:38:34.791Z","dateUpdated":"2026-09-18T17:53:37.480Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:11","lastModifiedDate":"2026-09-18 18:17:45","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90177","Ordinal":"1","Title":"bpf: Check pointer type for all atomic RMW paths","CVE":"CVE-2026-90177","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90177","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check pointer type for all atomic RMW paths\n\nAtomic RMW verification records an instruction pointer type only when the\ncurrent destination is PTR_TO_ARENA. A second path can therefore reach the\nsame instruction with an ordinary pointer without comparing it against the\nsaved arena type.\n\nThe post-verification fixup uses the saved type to rewrite the instruction\nto BPF_PROBE_ATOMIC for every path. Record the actual destination type for\nall atomic RMW paths so the existing mismatch check rejects incompatible\nuses of one instruction.","Type":"Description","Title":"bpf: Check pointer type for all atomic RMW paths"}]}}}