CVE-2026-90247
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-90247, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-17

Last updated on: 2026-09-17

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock leak in irq_work path stack_map_get_build_id_offset() introduced a per-CPU irq_work to defer mmap_read_unlock() from NMI context, and bpf_find_vma() later reused the same mmap_unlock_work. Both callers only check whether the work is busy before taking mmap_lock, so a nested caller can reuse the slot before the first caller queues it. Two read locks may then be acquired while only one deferred unlock runs, leaking a read lock and blocking exit_mmap(). Reserve the per-CPU slot before mmap_read_trylock(). Use the same wrapper in stackmap and bpf_find_vma() so both callers release the reservation on trylock failure. Keep rejecting the slot while the irq_work remains busy. Release it after the irq_work callback unlocks the mm.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-17
Last Modified
2026-09-17
Generated
2026-10-10
EPSS Evaluated
2026-10-09
NVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
Linux Linux eac9153f2b584c702cea02c1f1a57d85aa9aea42
Linux Linux eac9153f2b584c702cea02c1f1a57d85aa9aea42
Linux Linux eac9153f2b584c702cea02c1f1a57d85aa9aea42
Linux Linux a7f4da875c16f3b8bef0d9ec67528111045bfcd8
Linux Linux f1838da73cccb238b8be4ef464fce0168dc7ba84
Linux Linux 4.19.92
Linux Linux 5.4.7
Linux Linux 5.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90247. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart