Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parser kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents CPU migration, but does not establish an RCU read-side critical section. Consequently, BPF map operations can trigger WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser program. Hold the RCU read lock while running the program.
CVSS Score
HIGH
References
- https://git.kernel.org/stable/c/1d26a6e007d46babc7fa76e5a157dccf86cd55c0
- https://git.kernel.org/stable/c/21526f8a191a3c50622b8c10bd927870d780eae4
- https://git.kernel.org/stable/c/292846223eaddba890e40699d2ab82ee5671798c
- https://git.kernel.org/stable/c/37108861cf7bd909d4a372069bcd61c8f489e232
- https://git.kernel.org/stable/c/3c70d27e792a28bca650ddd8a9aa0fe3591ffec5
- https://git.kernel.org/stable/c/b0346dd64e4905291cc9c479f2e6cf1884ced4e6
- https://git.kernel.org/stable/c/b0e94ea63dbdcbfec9beb819cd5f8fa584809ef2
- https://git.kernel.org/stable/c/f392affef3c9ce64dfdde794df0579e0a7793440
FAQ
What is CVE-2026-90143?
CVE-2026-90143 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parser kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents CP...
How severe is CVE-2026-90143?
CVE-2026-90143 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-90143?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.