CVE-2026-53089

Source
https://cve.org/CVERecord?id=CVE-2026-53089
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53089.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-53089
Downstream
Published
2026-06-24T16:30:28Z
Modified
2026-09-04T03:30:56Z
Summary
bpf: Fix use-after-free in offloaded map/prog info fill
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix use-after-free in offloaded map/prog info fill

When querying info for an offloaded BPF map or program, bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() obtain the network namespace with get_net(dev_net(offmap->netdev)). However, the associated netdev's netns may be racing with teardown during netns destruction. If the netns refcount has already reached 0, get_net() performs a refcount_t increment on 0, triggering:

refcount_t: addition on 0; use-after-free.

Although rtnl_lock and bpf_devs_lock ensure the netdev pointer remains valid, they cannot prevent the netns refcount from reaching zero.

Fix this by using maybe_get_net() instead of get_net(). maybe_get_net() uses refcount_inc_not_zero() and returns NULL if the refcount is already zero, which causes ns_get_path_cb() to fail and the caller to return -ENOENT -- the correct behavior when the netns is being destroyed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53089.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
675fc275a3a2d905535207237402c6d8dcb5fa4b
Fixed
43d6848a2a6c92ccfd614d9f0bb6fd85b95dfa9d
Fixed
642943ae5bdacabc8109dc4a5e0ebb4a6b99ef3e
Fixed
fea55b034328feaafef75aee252f305e6f85a991
Fixed
5662dac41a3442aa378d7c405164903eb109fc05
Fixed
1a2dc103e16448d022a77ad5fc3234641436c4b7
Fixed
85dc711f742b192eb97c0e00b521312f5a7a415e
Fixed
a51e7fbe94a87e236631a83973d4f558310b2cd2
Fixed
a0c584fc18056709c8e047a82a6045d6c209f4ce

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53089.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.10.269
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.220
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.187
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.156
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.108
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.49
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53089.json"