{"id":"CVE-2026-90143","published":"2026-09-17T17:17:07.097","lastModified":"2026-09-18T18:17:43.690","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: kcm: Hold RCU read lock while running BPF parser\n\nkcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which\nprevents CPU migration, but does not establish an RCU read-side\ncritical section. Consequently, BPF map operations can trigger\nWARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser\nprogram.\n\nHold the RCU read lock while running the program.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/1d26a6e007d46babc7fa76e5a157dccf86cd55c0","tags":[]},{"url":"https://git.kernel.org/stable/c/21526f8a191a3c50622b8c10bd927870d780eae4","tags":[]},{"url":"https://git.kernel.org/stable/c/292846223eaddba890e40699d2ab82ee5671798c","tags":[]},{"url":"https://git.kernel.org/stable/c/37108861cf7bd909d4a372069bcd61c8f489e232","tags":[]},{"url":"https://git.kernel.org/stable/c/3c70d27e792a28bca650ddd8a9aa0fe3591ffec5","tags":[]},{"url":"https://git.kernel.org/stable/c/b0346dd64e4905291cc9c479f2e6cf1884ced4e6","tags":[]},{"url":"https://git.kernel.org/stable/c/b0e94ea63dbdcbfec9beb819cd5f8fa584809ef2","tags":[]},{"url":"https://git.kernel.org/stable/c/f392affef3c9ce64dfdde794df0579e0a7793440","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}