CVE-2026-90143
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parser kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which prevents CPU migration, but does not establish an RCU read-side critical section. Consequently, BPF map operations can trigger WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser program. Hold the RCU read lock while running the program.
Is your site exposed to CVE-2026-90143?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/1d26a6e007d46babc7fa76e5a157dccf86cd55c0
https://git.kernel.org/stable/c/21526f8a191a3c50622b8c10bd927870d780eae4
https://git.kernel.org/stable/c/292846223eaddba890e40699d2ab82ee5671798c
https://git.kernel.org/stable/c/37108861cf7bd909d4a372069bcd61c8f489e232
https://git.kernel.org/stable/c/3c70d27e792a28bca650ddd8a9aa0fe3591ffec5
https://git.kernel.org/stable/c/b0346dd64e4905291cc9c479f2e6cf1884ced4e6
https://git.kernel.org/stable/c/b0e94ea63dbdcbfec9beb819cd5f8fa584809ef2
https://git.kernel.org/stable/c/f392affef3c9ce64dfdde794df0579e0a7793440
Frequently Asked Questions
What is CVE-2026-90143? +
In the Linux kernel, the following vulnerability has been resolved:
net: kcm: Hold RCU read lock while running BPF parser
kcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() which
prevents CPU migration, but does not establish an RCU read-side
critical section. Consequently, BPF map operations can trigger
WARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparser
program.
Hold the RCU read lock while running the program.
How do I check if I'm vulnerable to CVE-2026-90143? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.