CVE-2026-90157

Source
https://cve.org/CVERecord?id=CVE-2026-90157
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90157.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90157
Downstream
Published
2026-09-17T16:06:49Z
Modified
2026-09-18T03:48:36Z
Summary
bpf: Reject negative optlen in cgroup getsockopt hook
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject negative optlen in cgroup getsockopt hook

A cgroup getsockopt BPF program can shrink ctx->optlen after the kernel getsockopt handler has run. The kernel-buffer variant, used by TCP_ZEROCOPY_RECEIVE, only rejects values larger than the original length.

If BPF writes a negative optlen, that value is accepted and propagated back to the TCP getsockopt code. It can then be passed to copy_to_sockptr() as a size_t and trigger the hardened usercopy bytes > INT_MAX warning.

Reject negative ctx.optlen in __cgroup_bpf_run_filter_getsockopt_kern(), matching the lower-bound validation already present in the sockptr-based getsockopt hook.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90157.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
08f61a34913558e06576e7b6318bf583f273c1be
Fixed
5b09d984b38b018b123c3a9e02a96bbc6468dbe5
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9cacf81f8161111db25f98e78a7a0e32ae142b3f
Fixed
554ba7195c4108726450e24480c8449990c2268c
Fixed
d02a12b4085ffe41ea750b1007f7a9c7aee2875a
Fixed
e6fbf0eba87f50084d67508898f6ad6fc7ff1ba2
Fixed
f68671b1a98d426c57864bd457c125fee14ac1a5
Fixed
2bdbe00454200fcb0110f31eeca8d906a3515e74
Fixed
31a89af4f513d750fec196e2bb6195a7d4473e9f
Fixed
1b5aacd5b2419b0790e955e466d389a61c79b4b1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.10.188
Fixed
5.10.270

Affected versions

v5.*
v5.10.188
v5.10.189
v5.10.190
v5.10.191
v5.10.192
v5.10.193
v5.10.194
v5.10.195
v5.10.196
v5.10.197
v5.10.198
v5.10.199
v5.10.200
v5.10.201
v5.10.202
v5.10.203
v5.10.204
v5.10.205
v5.10.206
v5.10.207
v5.10.208
v5.10.209
v5.10.210
v5.10.211
v5.10.212
v5.10.213
v5.10.214
v5.10.215
v5.10.216
v5.10.217
v5.10.218
v5.10.219
v5.10.220
v5.10.221
v5.10.222
v5.10.223
v5.10.224
v5.10.225
v5.10.226
v5.10.227
v5.10.228
v5.10.229
v5.10.230
v5.10.231
v5.10.232
v5.10.233
v5.10.234
v5.10.235
v5.10.236
v5.10.237
v5.10.238
v5.10.239
v5.10.240
v5.10.241
v5.10.242
v5.10.243
v5.10.244
v5.10.245
v5.10.246
v5.10.247
v5.10.248
v5.10.249
v5.10.250
v5.10.251
v5.10.252
v5.10.253
v5.10.254
v5.10.255
v5.10.256
v5.10.257
v5.10.258
v5.10.259
v5.10.260
v5.10.261
v5.10.262
v5.10.263
v5.10.264
v5.10.265
v5.10.266
v5.10.267
v5.10.268
v5.10.269

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90157.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90157.json"