CVE-2026-90195
CVE CVE-2026-90195EUVD EUVD-2026-81788Published 2026-09-17T16:07:14.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args On RV64, the ABI requires sign-extension for signed 1-byte and 2-byte kfunc args. However, the RV64 JIT currently does not perform sign-extension for such kfunc args. Before commit 7ce090afbf72 ("bpf: Infer zext_dst based on static register liveness analysis"), state pruning could potentially omit zero-extension of 32-bit subregisters, which inadvertently masked the above issue by making the args appear as if they had been properly sign-extended. After that commit, the problem is exposed, causing the kfunc_call/kfunc_call_test4 selftest to fail. Fix this by extending the existing sign-extension logic to handle signed 1-byte and 2-byte kfunc args as well.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.52; 443574b033876c85a35de4c65c14f7fe092222b2 <71dbd143be598954ae103feadd12692aeb0f2f88; patch: 7.2.6; 443574b033876c85a35de4c65c14f7fe092222b2 <f2aaa621591093cfe8224a25ef2f04a3b1e304b0; patch: 6.12.110; 443574b033876c85a35de4c65c14f7fe092222b2 <555fc6f1caf00ce7005e732b688da26c0dc3c5c5; 443574b033876c85a35de4c65c14f7fe092222b2 <801ae90f8ce099187e6224cec7d72d07a4df0324; patch: 7.3-rc1; patch: 0; 6.9
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.