CVE-2026-90284: fallo en Linux
firmware_loader: do not queue completed sysfs fallback requests
Publicada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 0.2%
probabilidad de explotación
0.2%top 90% de las CVE
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: do not queue completed sysfs fallback requests
fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to
pending_fw_head. device_add() publishes the fallback loading interface, so
a userspace helper which discovers the device by scanning sysfs can write 0
to the loading attribute and complete the request before it is queued as
pending.
In that interleaving firmware_loading_store() calls fw_state_done() while
pending_list still points to itself, so it cannot remove an entry from
pending_fw_head. The subsequent unconditional list_add() then queues an
already-completed fw_priv. Once the request is released, pending_fw_head
can retain a pointer to freed memory and the next fallback request can
fault while validating the list.
Only in-flight fallback requests need suspend or reboot abort handling. If
the request is already DONE after device_add(), return success from the
fallback path without sending another uevent, waiting again, or queueing it
as pending. This preserves the invariant that pending_fw_head contains only
active fallback requests.
Productos afectados
Linux · LinuxCVEs relacionadas — Linux
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referencias
https://git.kernel.org/stable/c/5a250bff75a446374c05622973b18b4ab662b504https://git.kernel.org/stable/c/6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7bhttps://git.kernel.org/stable/c/85aeb8fc61839098ae0942ccba86e669c08e75d4https://git.kernel.org/stable/c/93a2385730540105df8524447dcc11309ad280f9https://git.kernel.org/stable/c/b48373c901951fad1a26bd7c33ad91172b3945b5https://git.kernel.org/stable/c/c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7https://git.kernel.org/stable/c/ea33fac0df7fe7b49a4b27acb83e227b82317d1dhttps://git.kernel.org/stable/c/fb4824880b0dba0e7b3a497c46c642f979630392