External risk intelligence

Linux Kernel inetpeer Rate Limiting Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-90110

The vulnerability exists within the internal Linux kernel networking stack (inetpeer subsystem). While it is triggered by network packets, this functionality operates at a low level within the kernel to manage internal rate-limiting structures and is not a public-facing service, application, or interface that is typically deployed for direct internet interaction.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This issue involves a vulnerability in the Linux kernel's network peer management system that could allow attackers to bypass rate limits and potentially infer open UDP ports. The vulnerability arises from predictable internal data structures, which attackers could exploit to manipulate system behavior. While the core technology is fundamental to Linux networking, the specific attack vector and its direct business impact require further assessment for relevance.

  • Predictable kernel data structures can be manipulated.
  • Bypasses network rate limits, reveals UDP ports.
  • Confirm relevance and exposure to Linux systems.

Attack Path

How an attacker could exploit the issue

An attacker on the network could craft packets to manipulate the kernel's peer tracking system, which uses a predictable tree structure for storing information. By repeatedly triggering garbage collection and packet re-creation, an attacker could reset rate-limiting counters, allowing them to bypass defenses and potentially discover open UDP ports.

  • Network access required.
  • Crafted packets trigger predictable tree manipulation.
  • Bypass rate limits and infer open ports.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an off-path attacker to infer open UDP ports by manipulating the Linux kernel's peer tracking system. This manipulation can lead to the bypass of IP-keyed ICMP rate limits and reveal information about network services when supported by the advisory.

  • Network services information.
  • Predictable tree traversal and garbage collection.
  • UDP port discovery and rate limit bypass.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's inetpeer subsystem impacts infrastructure responsible for network traffic management. The first step for security and infrastructure teams is to identify all systems running the affected kernel version, assess their exposure to external network traffic, and confirm ownership for remediation.

  • Infrastructure and platform teams own this.
  • Verify network reachability and business criticality.
  • Plan kernel updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel inetpeer subsystem?

It is a core networking component that tracks remote network peers. It maintains data in a Red-Black tree structure to manage rate-limiting for outgoing ICMP traffic, helping ensure network stability by preventing any single source from overwhelming the system.

How does CVE-2026-90110 create a vulnerability?

The system previously used a predictable method to organize its internal tree. An attacker can exploit this lack of randomness to precisely manipulate the tree, triggering early data eviction and resetting rate-limit counters to bypass security controls.

What triggers this network manipulation?

An off-path attacker sends crafted network packets to force specific behaviors in the kernel's tree structure. Importantly, merely having the kernel running does not trigger the flaw; the attacker must intentionally send a sequence of packets to influence the garbage collection process.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal rates this as 'Unlikely' because the affected inetpeer subsystem functions deep within the kernel. It is not an internet-facing application or service; it handles internal rate-limiting logic rather than processing direct public requests.

What are the first steps to address this kernel issue?

Begin by auditing your environment to identify systems running the affected Linux kernel. Once identified, evaluate their exposure to untrusted network traffic and coordinate with your infrastructure team to schedule a kernel update during your next maintenance cycle.

References