Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-53090

7.8 · HIGH
Published Jun 24, 2026 linux CWE-253

Overview

CVE-2026-53090 is a high-severity vulnerability affecting linux linux_kernel. It was published on June 24, 2026 and has a CVSS 3.1 base score of 7.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix ld_{abs,ind} failure path analysis in subprogs

Usage of ld_{abs,ind} instructions got extended into subprogs some time

ago via commit 09b28d76eac4 ("bpf: Add abnormal return checks."). These

are only allowed in subprograms when the latter are BTF annotated and

have scalar return types.

The code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 +

exit) from legacy cBPF times. While the enforcement is on scalar return

types, the verifier must also simulate the path of abnormal exit if the

packet data load via ld_{abs,ind} failed.

This is currently not the case. Fix it by having the verifier simulate

both success and failure paths, and extend it in similar ways as we do

for tail calls. The success path (r0=unknown, continue to next insn) is

pushed onto stack for later validation and the r0=0 and return to the

caller is done on the fall-through side.

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.10, < 7.0.10 Affected

Frequently Asked Questions

What is CVE-2026-53090?

CVE-2026-53090 is a high-severity vulnerability affecting linux linux_kernel. It was published on June 24, 2026 and has a CVSS 3.1 base score of 7.8 (HIGH).

How severe is CVE-2026-53090?

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-53090?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-53090?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-53090 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.

Browse by year 2026