In the Linux kernel, the following vulnerability has been resolved: inetpeer: randomize RB-tree node comparison using SipHash The inetpeer rate… (CVE-2026-90110)
A critical vulnerability in the Linux kernel's inetpeer rate limiting system allowed off-path attackers to bypass IP-keyed ICMP rate limits and infer open UDP ports by exploiting deterministic Red-Black tree node comparisons. The issue was mitigated by randomizing the RB-tree node comparison using SipHash with a secret key, making tree traversal unpredictable to attackers.
AI Analysis
Technical Summary
The Linux kernel's inetpeer rate limiting system stores peer entries in a Red-Black tree keyed on remote IP addresses. The original deterministic lexicographical comparison allowed an off-path adversary to predict the tree topology and node traversal sequence. By triggering garbage collection when the tree size exceeded a threshold, an attacker could selectively evict inet_peer nodes, resetting their rate-limiting tokens upon recreation. This side-channel allowed bypassing ICMP rate limits and inferring open UDP ports. The vulnerability was mitigated by randomizing the RB-tree node comparison using SipHash with a secret key initialized once per system, making the tree layout and traversal paths unpredictable to attackers.
Potential Impact
An off-path attacker could bypass IP-keyed ICMP rate limits and infer open UDP ports on affected Linux kernel systems. This could facilitate reconnaissance and potentially aid further attacks. The CVSS v3.1 score is 9.4 (critical), indicating high confidentiality and integrity impact with low attack complexity and no privileges required.
Mitigation Recommendations
A fix is available that randomizes the RB-tree node comparison logic using SipHash with a secret key initialized at runtime. This breaks the deterministic eviction technique used by attackers. Users should apply the official Linux kernel update that includes this patch to mitigate the vulnerability.
In the Linux kernel, the following vulnerability has been resolved: inetpeer: randomize RB-tree node comparison using SipHash The inetpeer rate… (CVE-2026-90110)
Description
A critical vulnerability in the Linux kernel's inetpeer rate limiting system allowed off-path attackers to bypass IP-keyed ICMP rate limits and infer open UDP ports by exploiting deterministic Red-Black tree node comparisons. The issue was mitigated by randomizing the RB-tree node comparison using SipHash with a secret key, making tree traversal unpredictable to attackers.
CVSS v3.1
Score 9.4critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's inetpeer rate limiting system stores peer entries in a Red-Black tree keyed on remote IP addresses. The original deterministic lexicographical comparison allowed an off-path adversary to predict the tree topology and node traversal sequence. By triggering garbage collection when the tree size exceeded a threshold, an attacker could selectively evict inet_peer nodes, resetting their rate-limiting tokens upon recreation. This side-channel allowed bypassing ICMP rate limits and inferring open UDP ports. The vulnerability was mitigated by randomizing the RB-tree node comparison using SipHash with a secret key initialized once per system, making the tree layout and traversal paths unpredictable to attackers.
Potential Impact
An off-path attacker could bypass IP-keyed ICMP rate limits and infer open UDP ports on affected Linux kernel systems. This could facilitate reconnaissance and potentially aid further attacks. The CVSS v3.1 score is 9.4 (critical), indicating high confidentiality and integrity impact with low attack complexity and no privileges required.
Mitigation Recommendations
A fix is available that randomizes the RB-tree node comparison logic using SipHash with a secret key initialized at runtime. This breaks the deterministic eviction technique used by attackers. Users should apply the official Linux kernel update that includes this patch to mitigate the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cf89-f375-p3pc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-90110"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6aade52655bf5e2cf5edc1b2
Added to database: 09/19/2026, 01:28:06 UTC
Last enriched: 09/19/2026, 01:53:21 UTC
Last updated: 09/19/2026, 03:12:49 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.