← All Advisories

CVE-2026-90306

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-90306

Key Details

CVECVE-2026-90306
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9481/2: breakpoint: CFI breakpoints only on demand

This removes the stub hw_breakpoint_cfi_handler() from ARM, making

it not steal breakpoint type 0x03 (ARM_ENTRY_CFI_BREAKPOINT) unless

CFI is actively used in the kernel.

When not instrumenting with CFI, or when a breakpoint is issued in

userspace, we fall through to return 1 from hw_breakpoint_pending()

"unhandled fault" so userspace can make use of this breakpoint.

Tested with LKDTM and this command line:

echo CFI_FORWARD_PROTO > /sys/kernel/debug/provoke-crash/DIRECT

still works as expected. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90306
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90306