Privilege Escalation Vulnerability in Linux Kernel Affecting Non-SMP Builds
CVE-2026-90046

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90046?

The vulnerability in the Linux Kernel arises from the improper use of spin_trylock() in non-maskable interrupts (NMI) on uniprocessor (UP) systems. This issue can potentially lead to kernel crashes, particularly when BPF (Berkeley Packet Filter) programs that utilize these features are executed. Local attackers might exploit this vulnerability, enabling privilege escalation and allowing unauthorized access to system resources. The issue primarily affects non-SMP (Symmetric Multiprocessing) builds and has been recognized during code reviews without evidence of impact on real-world users.

Affected Version(s)

Linux 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 06c76d3c389ff504052f64b1acee44651bd847fa

Linux 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 68a069b407303e71db371df85036101e8ff59280

Linux 8c57b687e8331eb80e302a2c528b18b966a9ac7a < 3105ae628fb785d48b49256468be4f21a7b3cfc0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.