7.8

CVE-2026-90291

module/dups: Fix use-after-free in kmod_dup_req lifetime handling

In the Linux kernel, the following vulnerability has been resolved:

module/dups: Fix use-after-free in kmod_dup_req lifetime handling

The kmod dups code uses RCU to ensure that a kmod_dup_req instance is freed
only after it is no longer referenced. When releasing an instance, the
kmod_dup_request_delete() function removes the kmod_dup_req from the
dup_kmod_reqs list, waits via synchronize_rcu() and finally frees it.
However, this doesn't work correctly because parallel users referencing the
instance in kmod_dup_request_exists_wait() don't enter an RCU read-side
critical section. This can result in a use-after-free.

The kmod_dup_request_exists_wait() function may need to hold a valid
reference to a kmod_dup_req instance across a blocking wait until the
corresponding modprobe command completes. This makes it unsuitable for RCU.

Fix the issue by changing the lifecycle management of kmod_dup_req to use
reference counting.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8660484ed1cf3261e89e0bad94c6395597e87599
Version < 2c85e0fb528e039aa8ea1e9c2a1f64347f990541
Status affected
Version 8660484ed1cf3261e89e0bad94c6395597e87599
Version < b2709aad7599f6fd957939b60f4a8323c8f08072
Status affected
Version 8660484ed1cf3261e89e0bad94c6395597e87599
Version < cd2396fc9684d2cfd3f3c3f09c79d6d9d725b0ca
Status affected
Version 8660484ed1cf3261e89e0bad94c6395597e87599
Version < 5eecb11b543f9f417bcf0dea239ff99c6af65dbd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.4
Status affected
Version 0
Version < 6.4
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2c85e0fb528e039aa8ea1e9c2a1f64347f990541
https://git.kernel.org/stable/c/b2709aad7599f6fd957939b60f4a8323c8f08072
https://git.kernel.org/stable/c/cd2396fc9684d2cfd3f3c3f09c79d6d9d725b0ca
https://git.kernel.org/stable/c/5eecb11b543f9f417bcf0dea239ff99c6af65dbd