-
CVE-2026-90140
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:06:37
- Zuletzt bearbeitet 17.09.2026 17:17:06
- Erkennungen
cuse: wait for pending RCU callbacks on module exit
In the Linux kernel, the following vulnerability has been resolved:
cuse: wait for pending RCU callbacks on module exit
Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"),
fuse_conn_put() frees the fuse_conn through call_rcu() rather than
synchronously. For cuse, fc->release is cuse_fc_release(), which
lives in the cuse module. If the module is removed before the RCU
grace period ends, the callback jumps into freed module memory:
userspace / module unload | RCU softirq
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
close(/dev/cuse) |
cuse_channel_release() |
fuse_dev_release() |
fuse_conn_put(fch->conn) |
call_rcu(delayed_release) ------+---> callback queued
|
rmmod cuse |
cuse_exit() |
cuse_channel_destroy() |
... |
return |
|
<module text freed> |
| rcu_do_batch()
| delayed_release()
| fc->release()
| -> cuse_fc_release()
| ^^^ freed text!
The freed module text is unmapped by vfree(), so the jump into the
stale callback triggers a page-fault Oops. If the virtual address
is subsequently reused, the callback could execute unrelated code
(undefined behaviour).
Fix this by calling rcu_barrier() in cuse_exit() so that any pending
fuse_conn release callback completes before the module is removed.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
bfbab62ca69f72bcd14ea30de1fb98f6080ad464
Version <
7fe415e1cd8fa875be263670c0ab47109818abb6
Status
affected
Version
a8f650b93e55764ca9ff8e1ddebc151f57024086
Version <
45ae914b2f6ea56fc2f1c017fdee4e995bcb4c0e
Status
affected
Version
535e9bd0e8f8d8cfdc29de7cdb902b5041427fe6
Version <
ac5c499413385cea3e0220d6050408d50842891d
Status
affected
Version
053fc4f755ad43cf35210677bcba798ccdc48d0c
Version <
a1b46aee33d83f14ed62d7fdef1a91d3e0b732a9
Status
affected
Version
053fc4f755ad43cf35210677bcba798ccdc48d0c
Version <
389bd349ddbcf90dbd8a4f2a4ab6e552d53df134
Status
affected
Version
053fc4f755ad43cf35210677bcba798ccdc48d0c
Version <
c40f3f24839f8404325a2099e26c2a04786ae309
Status
affected
Version
053fc4f755ad43cf35210677bcba798ccdc48d0c
Version <
4deb3edead0c0e172cc7349e8855d741d3c5e162
Status
affected
Version
5.15.166
Version <
5.15.221
Status
affected
Version
6.1.107
Version <
6.1.188
Status
affected
Version
6.6.48
Version <
6.6.157
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.8
Status
affected
Version
0
Version <
6.8
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.109 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/7fe415e1cd8fa875be263670c0ab47109818abb6
https://git.kernel.org/stable/c/45ae914b2f6ea56fc2f1c017fdee4e995bcb4c0e
https://git.kernel.org/stable/c/ac5c499413385cea3e0220d6050408d50842891d
https://git.kernel.org/stable/c/a1b46aee33d83f14ed62d7fdef1a91d3e0b732a9
https://git.kernel.org/stable/c/389bd349ddbcf90dbd8a4f2a4ab6e552d53df134
https://git.kernel.org/stable/c/c40f3f24839f8404325a2099e26c2a04786ae309
https://git.kernel.org/stable/c/4deb3edead0c0e172cc7349e8855d741d3c5e162