CVE-2026-90160

Source
https://cve.org/CVERecord?id=CVE-2026-90160
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90160.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90160
Downstream
Published
2026-09-17T16:06:51Z
Modified
2026-09-18T03:48:36Z
Summary
lwt_bpf: Restore reserved headroom after xmit program
Details

In the Linux kernel, the following vulnerability has been resolved:

lwt_bpf: Restore reserved headroom after xmit program

ip_finish_output2() expands an skb to LL_RESERVED_SPACE(dev) before LWT xmit. An LWT_XMIT BPF program can then modify the skb head and still return BPF_OK, so bpf_xmit() rechecks the remaining headroom before the skb continues to neighbour output.

That recheck uses dst->dev->hard_header_len. This is not enough for the neighbour cached-header path: neigh_hh_output() copies the cached hardware header using the aligned hh_cache size, HH_DATA_MOD for short headers or HH_DATA_ALIGN(hh_len) otherwise.

On Ethernet, hard_header_len is 14 but the cached copy needs 16 bytes. If an LWT_XMIT BPF program calls bpf_skb_change_head(skb, 1, 0), the skb can still have 15 bytes of headroom after the program. The existing check accepts that, after which neigh_hh_output() hits its headroom warning and drops the skb.

Use LL_RESERVED_SPACE(dst->dev) in the post-BPF headroom check to match the reservation made before LWT xmit.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90160.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3a0af8fd61f90920f6fa04e4f1e9a6a73c1b4fd2
Fixed
753e5cdcca5474d230d62bb3489e5168ab27c272
Fixed
c488071c3441fa34f5a87cd6c12ce2cc6304f20e
Fixed
a38c0eb447e2dd0120a2ebcdba470f9505ac8907
Fixed
de2b2004e16f2930eb689175e2c1998b0a68d499
Fixed
7d043e24520a273c362be5dd7d9c82796879a49b
Fixed
7cf561843ed0ad57501892a65abb77957e6c800f
Fixed
179a5b2171573d94a25c9aa8e1c9f9ac352ad316
Fixed
5fe7007aed9ad069b2bd77e5d0c875c64f5c0269

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90160.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90160.json"