CVE-2026-90143

high

Description

In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parser kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents CPU migration, but does not establish an RCU read-side critical section. Consequently, BPF map operations can trigger WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser program. Hold the RCU read lock while running the program.

References

https://git.kernel.org/stable/c/f392affef3c9ce64dfdde794df0579e0a7793440

https://git.kernel.org/stable/c/b0e94ea63dbdcbfec9beb819cd5f8fa584809ef2

https://git.kernel.org/stable/c/b0346dd64e4905291cc9c479f2e6cf1884ced4e6

https://git.kernel.org/stable/c/3c70d27e792a28bca650ddd8a9aa0fe3591ffec5

https://git.kernel.org/stable/c/37108861cf7bd909d4a372069bcd61c8f489e232

https://git.kernel.org/stable/c/292846223eaddba890e40699d2ab82ee5671798c

https://git.kernel.org/stable/c/21526f8a191a3c50622b8c10bd927870d780eae4

https://git.kernel.org/stable/c/1d26a6e007d46babc7fa76e5a157dccf86cd55c0

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-18

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0021