---
id: CVE-2026-90312
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Check load-acquire src ptr type before the load

  check_atomic_load() calls check_load_mem() before atomic_ptr_type_ok().
  For a load-acquire that fetches into its o…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Check load-acquire src ptr type before the load

  check_atomic_load() calls check_load_mem() before atomic_ptr_type_ok().
  For a load-acquire that fetches into its o…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9 <
    6ee7b00888498cf387dd30729e18a05328b94709
  - >-
    Linux >= c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9 <
    422a416041172af1ac610736d5f556d22b31b115
  - >-
    Linux >= c03bb2fa327e4c25d6c5360a8803a4b1cdc2d0b9 <
    b87803391baa7e0bef60549d8841f12e549ad057
  - Linux 6.15
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:53.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90312'
references:
  - url: 'https://git.kernel.org/stable/c/422a416041172af1ac610736d5f556d22b31b115'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6ee7b00888498cf387dd30729e18a05328b94709'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b87803391baa7e0bef60549d8841f12e549ad057'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00173
epssPercentile: 0.05913
ingestedAt: '2026-09-17T16:21:47.826Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: Check load-acquire src ptr type before the load

check_atomic_load() calls check_load_mem() before atomic_ptr_type_ok().
For a load-acquire that fetches into its own source register (dst_reg ==
src_reg), check_load_mem() overwrites src_reg's type with the type of the
loaded value, so the subsequent atomic_ptr_type_ok() no longer sees the
source pointer and fails to reject the disallowed types (ctx, pkt,
flow_keys, sock).

Since bpf_convert_ctx_accesses() does not rewrite atomic loads, the raw
access to the underlying kernel object is left in place. The destination
type is taken from the ctx access itself, so a load-acquire of the sk
field of struct __sk_buff for example leaves the register typed as
PTR_TO_SOCK_COMMON_OR_NULL, which type_is_sk_pointer() does not match
either, while it actually holds unconverted struct sk_buff bytes. Once
the NULL check has passed this is a type confusion, not just a leak of
kernel data.

Validate src_reg with check_reg_arg() and check the source pointer type
with atomic_ptr_type_ok() before the load again, mirroring
check_atomic_rmw(). Out-of-range register numbers are already rejected
earlier by check_and_resolve_insns() (commit 503d21ef8eac ("bpf: Do
register range validation early")), and the only exemption there,
is_stack_arg_ldx(), requires BPF_LDX | BPF_MEM | BPF_DW and thus never
matches a BPF_ATOMIC insn. atomic_ptr_type_ok() can therefore not
dereference register state out of bounds, that is, the out-of-bounds
read addressed by the Fixes commit below does not reappear (as proven
also via selftest).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
