CVE-2026-90143

Source
https://cve.org/CVERecord?id=CVE-2026-90143
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90143.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90143
Downstream
Published
2026-09-17T16:06:39Z
Modified
2026-09-18T03:48:35Z
Summary
net: kcm: Hold RCU read lock while running BPF parser
Details

In the Linux kernel, the following vulnerability has been resolved:

net: kcm: Hold RCU read lock while running BPF parser

kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents CPU migration, but does not establish an RCU read-side critical section. Consequently, BPF map operations can trigger WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser program.

Hold the RCU read lock while running the program.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90143.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9b73896a81dc68a638a011877b7344b252f92276
Fixed
37108861cf7bd909d4a372069bcd61c8f489e232
Fixed
3c70d27e792a28bca650ddd8a9aa0fe3591ffec5
Fixed
1d26a6e007d46babc7fa76e5a157dccf86cd55c0
Fixed
b0e94ea63dbdcbfec9beb819cd5f8fa584809ef2
Fixed
21526f8a191a3c50622b8c10bd927870d780eae4
Fixed
292846223eaddba890e40699d2ab82ee5671798c
Fixed
f392affef3c9ce64dfdde794df0579e0a7793440
Fixed
b0346dd64e4905291cc9c479f2e6cf1884ced4e6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90143.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.9.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90143.json"