Answer in brief
CVE-2026-90157 records a Unknown severity vulnerability in bpf: Reject negative optlen in cgroup getsockopt hook. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=08f61a34913558e06576e7b6318bf583f273c1be <5b09d984b38b018b123c3a9e02a96bbc6468dbe5 || >=9cacf81f8161111db25f98e78a7a0e32ae142b3f <554ba7195c4108726450e24480c8449990c2268c || >=9cacf81f8161111db25f98e78a7a0e32ae142b3f <d02a12b4085ffe41ea750b1007f7a9c7aee2875a || >=9cacf81f8161111db25f98e78a7a0e32ae142b3f <e6fbf0eba87f50084d67508898f6ad6fc7ff1ba2 || >=9cacf81f8161111db25f98e78a7a0e32ae142b3f <f68671b1a98d426c57864bd457c125fee14ac1a5 || >=9cacf81f8161111db25f98e78a7a0e32ae142b3f <2bdbe00454200fcb0110f31eeca8d906a3515e74 || >=9cacf81f8161111db25f98e78a7a0e32ae142b3f <31a89af4f513d750fec196e2bb6195a7d4473e9f || >=9cacf81f8161111db25f98e78a7a0e32ae142b3f <1b5aacd5b2419b0790e955e466d389a61c79b4b1 || >=5.10.188 <5.10.270 | 5b09d984b38b018b123c3a9e02a96bbc6468dbe5, 554ba7195c4108726450e24480c8449990c2268c, d02a12b4085ffe41ea750b1007f7a9c7aee2875a, e6fbf0eba87f50084d67508898f6ad6fc7ff1ba2, f68671b1a98d426c57864bd457c125fee14ac1a5, 2bdbe00454200fcb0110f31eeca8d906a3515e74, 31a89af4f513d750fec196e2bb6195a7d4473e9f, 1b5aacd5b2419b0790e955e466d389a61c79b4b1, 5.10.270 |
| Linux/Linuxgeneric | 5.12 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt hook A cgroup getsockopt BPF program can shrink ctx->optlen after the kernel getsockopt handler has run. The kernel-buffer variant, used by TCP_ZEROCOPY_RECEIVE, only rejects values larger than the original length. If BPF writes a negative optlen, that value is accepted and propagated back to the TCP getsockopt code. It can then be passed to copy_to_sockptr() as a size_t and trigger the hardened usercopy bytes > INT_MAX warning. Reject negative ctx.optlen in __cgroup_bpf_run_filter_getsockopt_kern(), matching the lower-bound validation already present in the sockptr-based getsockopt hook.
Quoted source text, attributed separately from HOL analysis.