CVE-2026-90250
In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix storage null-ptr-deref after replacing prog Syzkaller reported a storage null-ptr-deref issue after replacing prog. This occurs in the following scenario: 1. prog A, an empty prog, is attached to a cgrp. 2. prog B uses BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE and calls the bpf_get_local_storage helper. 3. link_update is called to replace prog A with prog B. The reason is that __cgroup_bpf_replace fails to alloc and assign the required cgrp storage for the incoming replacement prog. Consequently, the new prog inherits an uninit storage, leading to null-ptr-deref panic when kick the new prog. Fix this by rejecting a link update if new_prog's cgroup storage is incompatible with link->prog.
Affected versions
Linux kernel versions
5.7
and later are affected. Fixed in
6.12.110,
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
4 totalFrequently asked questions
-
What is CVE-2026-90250?
CVE-2026-90250 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.7 onward and has been patched in 6.12.110, 6.18.52, 7.2.6 and others. CVE-2026-90250 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-90250?
Yes. CVE-2026-90250 has been patched. Fixed versions include 6.12.110, 6.18.52, 7.2.6 and others. If you are running Linux kernel 5.7 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-90250 actively exploited?
No. CVE-2026-90250 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.