Privilege Escalation Vulnerability in Linux Kernel Affecting Non-SMP Builds
CVE-2026-90046
What is CVE-2026-90046?
The vulnerability in the Linux Kernel arises from the improper use of spin_trylock() in non-maskable interrupts (NMI) on uniprocessor (UP) systems. This issue can potentially lead to kernel crashes, particularly when BPF (Berkeley Packet Filter) programs that utilize these features are executed. Local attackers might exploit this vulnerability, enabling privilege escalation and allowing unauthorized access to system resources. The issue primarily affects non-SMP (Symmetric Multiprocessing) builds and has been recognized during code reviews without evidence of impact on real-world users.
Affected Version(s)
Linux 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 06c76d3c389ff504052f64b1acee44651bd847fa
Linux 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 68a069b407303e71db371df85036101e8ff59280
Linux 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 3105ae628fb785d48b49256468be4f21a7b3cfc0