CVE-2026-90177
Description
AI Translation Available
In the Linux kernel, the following vulnerability has been resolved:
bpf: Check pointer type for all atomic RMW paths
Atomic RMW verification records an instruction pointer type only when the
current destination is PTR_TO_ARENA. A second path can therefore reach the
same instruction with an ordinary pointer without comparing it against the
saved arena type.
The post-verification fixup uses the saved type to rewrite the instruction
to BPF_PROBE_ATOMIC for every path. Record the actual destination type for
all atomic RMW paths so the existing mismatch check rejects incompatible
uses of one instruction.
https://git.kernel.org/stable/c/4bc49ae344d65cfcef738f281ac575cf73ca2fc5
https://git.kernel.org/stable/c/eb287c6e81dedef92da01eb947f380d0aae513c3