-
CVE-2026-90284
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:08:13
- Zuletzt bearbeitet 17.09.2026 17:17:25
- Erkennungen
firmware_loader: do not queue completed sysfs fallback requests
In the Linux kernel, the following vulnerability has been resolved: firmware_loader: do not queue completed sysfs fallback requests fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to pending_fw_head. device_add() publishes the fallback loading interface, so a userspace helper which discovers the device by scanning sysfs can write 0 to the loading attribute and complete the request before it is queued as pending. In that interleaving firmware_loading_store() calls fw_state_done() while pending_list still points to itself, so it cannot remove an entry from pending_fw_head. The subsequent unconditional list_add() then queues an already-completed fw_priv. Once the request is released, pending_fw_head can retain a pointer to freed memory and the next fallback request can fault while validating the list. Only in-flight fallback requests need suspend or reboot abort handling. If the request is already DONE after device_add(), return success from the fallback path without sending another uevent, waiting again, or queueing it as pending. This preserves the invariant that pending_fw_head contains only active fallback requests.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ecb739cf15a9bae040ce6b60209b78b92512d120
Version <
c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7
Status
affected
Version
75d95e2e39b27f733f21e6668af1c9893a97de5e
Version <
93a2385730540105df8524447dcc11309ad280f9
Status
affected
Version
75d95e2e39b27f733f21e6668af1c9893a97de5e
Version <
ea33fac0df7fe7b49a4b27acb83e227b82317d1d
Status
affected
Version
75d95e2e39b27f733f21e6668af1c9893a97de5e
Version <
5a250bff75a446374c05622973b18b4ab662b504
Status
affected
Version
75d95e2e39b27f733f21e6668af1c9893a97de5e
Version <
85aeb8fc61839098ae0942ccba86e669c08e75d4
Status
affected
Version
75d95e2e39b27f733f21e6668af1c9893a97de5e
Version <
6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b
Status
affected
Version
75d95e2e39b27f733f21e6668af1c9893a97de5e
Version <
fb4824880b0dba0e7b3a497c46c642f979630392
Status
affected
Version
75d95e2e39b27f733f21e6668af1c9893a97de5e
Version <
b48373c901951fad1a26bd7c33ad91172b3945b5
Status
affected
Version
67cf0fbcac0d42d4d4686cddc1e39f465bbfec37
Status
affected
Version
d09639528b66b5c7c20dc8f7fb8928aacabd40bb
Status
affected
Version
c14a54675db7131791402fa22fb0fa6da1f5fb66
Status
affected
Version
5.10.58
Version <
5.10.270
Status
affected
Version
4.19.203
Version <
4.20
Status
affected
Version
5.4.140
Version <
5.5
Status
affected
Version
5.13.10
Version <
5.14
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.14
Status
affected
Version
0
Version <
5.14
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.116 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7
https://git.kernel.org/stable/c/93a2385730540105df8524447dcc11309ad280f9
https://git.kernel.org/stable/c/ea33fac0df7fe7b49a4b27acb83e227b82317d1d
https://git.kernel.org/stable/c/5a250bff75a446374c05622973b18b4ab662b504
https://git.kernel.org/stable/c/85aeb8fc61839098ae0942ccba86e669c08e75d4
https://git.kernel.org/stable/c/6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b
https://git.kernel.org/stable/c/fb4824880b0dba0e7b3a497c46c642f979630392
https://git.kernel.org/stable/c/b48373c901951fad1a26bd7c33ad91172b3945b5