{"id":"CVE-2026-90250","published":"2026-09-17T17:17:21.237","lastModified":"2026-09-17T17:17:21.237","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, cgroup: Fix storage null-ptr-deref after replacing prog\n\nSyzkaller reported a storage null-ptr-deref issue after replacing prog.\nThis occurs in the following scenario:\n1. prog A, an empty prog, is attached to a cgrp.\n2. prog B uses BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE and calls the\n   bpf_get_local_storage helper.\n3. link_update is called to replace prog A with prog B.\n\nThe reason is that __cgroup_bpf_replace fails to alloc and assign the\nrequired cgrp storage for the incoming replacement prog. Consequently,\nthe new prog inherits an uninit storage, leading to null-ptr-deref panic\nwhen kick the new prog.\n\nFix this by rejecting a link update if new_prog's cgroup storage is\nincompatible with link->prog.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/12feca126831556dc7fabe5a3ba28fbd328768b6","tags":[]},{"url":"https://git.kernel.org/stable/c/1ab3da12061d7ccb099f7e925fa2d865967a316a","tags":[]},{"url":"https://git.kernel.org/stable/c/3f562c537e9ecf4bc5e206cfffc2cc047f1b7e94","tags":[]},{"url":"https://git.kernel.org/stable/c/a033c950f6731be88a7da98604ed78f302f15b80","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}