CVE-2026-90247
CVE CVE-2026-90247EUVD EUVD-2026-81840Published 2026-09-17T16:07:49.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock leak in irq_work path stack_map_get_build_id_offset() introduced a per-CPU irq_work to defer mmap_read_unlock() from NMI context, and bpf_find_vma() later reused the same mmap_unlock_work. Both callers only check whether the work is busy before taking mmap_lock, so a nested caller can reuse the slot before the first caller queues it. Two read locks may then be acquired while only one deferred unlock runs, leaking a read lock and blocking exit_mmap(). Reserve the per-CPU slot before mmap_read_trylock(). Use the same wrapper in stackmap and bpf_find_vma() so both callers release the reservation on trylock failure. Keep rejecting the slot while the irq_work remains busy. Release it after the irq_work callback unlocks the mm.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux a7f4da875c16f3b8bef0d9ec67528111045bfcd8; f1838da73cccb238b8be4ef464fce0168dc7ba84; patch: 7.2.6; patch: 0; patch: 6.18.52; patch: 7.3-rc1; 5.4.7 <5.5; eac9153f2b584c702cea02c1f1a57d85aa9aea42 <fa9dcacdcdf487f0ffef64bf67622f1caed509f1; eac9153f2b584c702cea02c1f1a57d85aa9aea42 <a052ad5edccf5319f50ed955de4368f8318a9f20; 4.19.92 <4.20; 5.5; eac9153f2b584c702cea02c1f1a57d85aa9aea42 <051f2da26ce377f683b938a3382e0f16d02f3139
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.