CVE-2026-90157

Unknown

Last modified

CVE-2026-90157 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt hook A cgroup getsockopt BPF program can shrink ctx->optlen after the kernel getsockopt handler has run. The kernel-buffer variant, used by TCP_ZEROCOPY_RECEIVE, only rejects values larger than the original length. If BPF writes a negative optlen, that value is accepted and propagated back to the TCP getsockopt code.

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt hook A cgroup getsockopt BPF program can shrink ctx->optlen after the kernel getsockopt handler has run. The kernel-buffer variant, used by TCP_ZEROCOPY_RECEIVE, only rejects values larger than the original length. If BPF writes a negative optlen, that value is accepted and propagated back to the TCP getsockopt code. It can then be passed to copy_to_sockptr() as a size_t and trigger the hardened usercopy bytes > INT_MAX warning. Reject negative ctx.optlen in __cgroup_bpf_run_filter_getsockopt_kern(), matching the lower-bound validation already present in the sockptr-based getsockopt hook.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 08f61a34913558e06576e7b6318bf583f273c1be, < 5b09d984b38b018b123c3a9e02a96bbc6468dbe5; >= 9cacf81f8161111db25f98e78a7a0e32ae142b3f, < 554ba7195c4108726450e24480c8449990c2268c; >= 9cacf81f8161111db25f98e78a7a0e32ae142b3f, < d02a12b4085ffe41ea750b1007f7a9c7aee2875a; >= 9cacf81f8161111db25f98e78a7a0e32ae142b3f, < e6fbf0eba87f50084d67508898f6ad6fc7ff1ba2; >= 9cacf81f8161111db25f98e78a7a0e32ae142b3f, < f68671b1a98d426c57864bd457c125fee14ac1a5; >= 9cacf81f8161111db25f98e78a7a0e32ae142b3f, < 2bdbe00454200fcb0110f31eeca8d906a3515e74; >= 9cacf81f8161111db25f98e78a7a0e32ae142b3f, < 31a89af4f513d750fec196e2bb6195a7d4473e9f; >= 9cacf81f8161111db25f98e78a7a0e32ae142b3f, < 1b5aacd5b2419b0790e955e466d389a61c79b4b1; >= 5.10.188, < 5.10.270
LinuxLinux5.12

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90157?
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt hook A cgroup getsockopt BPF program can shrink ctx->optlen after the kernel getsockopt handler has run. The kernel-buffer variant, used by TCP_ZEROCOPY_RECEIVE, only rejects values larger than the original length. If BPF writes a negative optlen, that value is accepted and propagated back to the TCP getsockopt code. It can then be passed to copy_to_sockptr() as a size_t and trigger the hardened usercopy bytes > INT_MAX warning. Reject negative ctx.optlen in __cgroup_bpf_run_filter_getsockopt_kern(), matching the lower-bound validation already present in the sockptr-based getsockopt hook.
How severe is CVE-2026-90157?
Severity scoring for CVE-2026-90157 is pending analysis.
How do I fix CVE-2026-90157?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90157?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST