External risk intelligence

Linux Kernel SUNRPC Socket Callback Race Condition.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90235

The vulnerability exists within the Linux kernel SUNRPC (Remote Procedure Call) implementation. While SUNRPC can handle network traffic, it is typically used for internal services like NFS (Network File System). Exposure to the public internet is uncommon, as these services are generally restricted to trusted internal networks or specific, protected communication channels.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This issue involves a flaw in the Linux kernel's handling of shared socket callbacks, which could lead to unexpected behavior or potential exploitation if not addressed. The primary concern is to confirm if this specific kernel functionality is utilized within our environment.

  • Handles shared socket callback race conditions.
  • Matters for confirming Linux kernel SUNRPC usage.
  • Assess relevance and confirm exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by triggering a race condition within the Linux kernel's SUNRPC (Remote Procedure Call) component. This occurs when the system manages socket callbacks on live network connections. If another processor accesses a stale snapshot of these callbacks while they are being updated, it can lead to unexpected behavior, potentially allowing an attacker to influence critical system operations.

  • Entry condition: Network access to a vulnerable system.
  • Trigger point: Concurrently accessing shared socket callbacks.
  • Resulting risk: Complete system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect the handling of shared socket callbacks within the Linux kernel's SUNRPC implementation. When SUNRPC manages socket callbacks for AF_LOCAL, UDP, or TCP sockets, a race condition might occur. This could lead to outdated callback pointers being invoked, potentially impacting service behavior when supported by the advisory.

  • Kernel socket callback pointers at risk.
  • Race condition may invoke stale callbacks.
  • Unpredictable service behavior may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability within the Linux kernel's SUNRPC component likely impacts infrastructure and platform teams responsible for systems utilizing network file sharing or other RPC-dependent services. The initial step should be to inventory all systems running the affected kernel, confirm exposure to untrusted networks, and identify the accountable system owners before planning remediation.

  • Infrastructure and platform teams own remediation.
  • Verify kernel exposure and asset criticality.
  • Plan maintenance for kernel updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel SUNRPC component?

SUNRPC stands for Sun Remote Procedure Call. It is a fundamental part of the Linux kernel that allows different programs or systems to communicate. It is most commonly used to power Network File System (NFS) services, which allow computers to share files over a network as if they were stored on a local drive.

What is the vulnerability in CVE-2026-90235?

This vulnerability is a race condition. It occurs because the kernel handles certain socket information using plain instructions rather than protected, atomic ones. When the kernel replaces callback functions on a live network socket, there is a tiny window of time where another processor might try to use the old, now-invalid function, leading to unstable or unpredictable system behavior.

How can this vulnerability be triggered?

An attacker would need the ability to interact with a system's network socket management. The issue specifically arises during the connection teardown or updates of AF_LOCAL, UDP, or TCP sockets managed by SUNRPC. The bug is not triggered by static configurations; it requires active, concurrent processing where one CPU modifies callback pointers while another CPU attempts to access them simultaneously.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal labels the risk as Unlikely. Because SUNRPC is primarily used for internal services like NFS, these interfaces are rarely exposed directly to the public internet. Systems are generally safer when these services are kept behind firewalls or on isolated internal networks rather than being reachable from untrusted external traffic.

What should I do if I run affected systems?

The first step is to inventory your infrastructure to identify which systems are running Linux kernels that utilize SUNRPC for network file sharing. Once identified, verify if those services are accessible from untrusted networks. Coordinate with your platform and infrastructure teams to plan and apply the necessary kernel updates provided by your distribution vendor.

References