CVE-2026-90143
Last modified
CVE-2026-90143 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parser kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents CPU migration, but does not establish an RCU read-side critical section. Consequently, BPF map operations can trigger WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser program. Hold the RCU read lock while running the program..
Description
In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parser kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents CPU migration, but does not establish an RCU read-side critical section. Consequently, BPF map operations can trigger WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser program. Hold the RCU read lock while running the program.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 9b73896a81dc68a638a011877b7344b252f92276, < 37108861cf7bd909d4a372069bcd61c8f489e232; >= 9b73896a81dc68a638a011877b7344b252f92276, < 3c70d27e792a28bca650ddd8a9aa0fe3591ffec5; >= 9b73896a81dc68a638a011877b7344b252f92276, < 1d26a6e007d46babc7fa76e5a157dccf86cd55c0; >= 9b73896a81dc68a638a011877b7344b252f92276, < b0e94ea63dbdcbfec9beb819cd5f8fa584809ef2; >= 9b73896a81dc68a638a011877b7344b252f92276, < 21526f8a191a3c50622b8c10bd927870d780eae4; >= 9b73896a81dc68a638a011877b7344b252f92276, < 292846223eaddba890e40699d2ab82ee5671798c; >= 9b73896a81dc68a638a011877b7344b252f92276, < f392affef3c9ce64dfdde794df0579e0a7793440; >= 9b73896a81dc68a638a011877b7344b252f92276, < b0346dd64e4905291cc9c479f2e6cf1884ced4e6 |
| Linux | Linux | 4.9 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90143?
How severe is CVE-2026-90143?
How do I fix CVE-2026-90143?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90138In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90139In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9014The WP Promoter plugin for WordPress is vulnerable to unauth…5.3
- CVE-2026-90140In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90141In the Linux kernel, the following vulnerability has been re…7.3
- CVE-2026-90142In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90144In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90145In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-90146In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90147In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90148In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90149In the Linux kernel, the following vulnerability has been re…7.5
Are you affected by CVE-2026-90143?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
