CVE-2026-90306

Source
https://cve.org/CVERecord?id=CVE-2026-90306
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90306.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90306
Downstream
Published
2026-09-17T16:08:28Z
Modified
2026-09-18T03:48:37Z
Summary
ARM: 9481/2: breakpoint: CFI breakpoints only on demand
Details

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9481/2: breakpoint: CFI breakpoints only on demand

This removes the stub hw_breakpoint_cfi_handler() from ARM, making it not steal breakpoint type 0x03 (ARM_ENTRY_CFI_BREAKPOINT) unless CFI is actively used in the kernel.

When not instrumenting with CFI, or when a breakpoint is issued in userspace, we fall through to return 1 from hw_breakpoint_pending() "unhandled fault" so userspace can make use of this breakpoint.

Tested with LKDTM and this command line: echo CFI_FORWARD_PROTO > /sys/kernel/debug/provoke-crash/DIRECT still works as expected.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90306.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c3f89986fde7bb9ccc86a901bf28e1f7d69fc3b3
Fixed
22107402c2669b0163d43cc68901a2c4a59fa43a
Fixed
314f1a6762b5d51b37784ed7dc701d4c3d893703
Fixed
da64b150e4b7bee615b33ab21f3137c31ec36922
Fixed
8ed9bff906cf8036531d1559f10e82733a52b41f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90306.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90306.json"