-

CVE-2026-90303

ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults

When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set,
a user fault may trigger show_pte() without any lock.
If another thread in the same process concurrently calls munmap(),
the page table pages may be freed while show_pte() is still traversing
them, causing a use-after-free in show_pte().

If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table
of PMD are freed when show_pte() is running.

Acquire mmap_write_lock() around show_pte() for user faults to fix the
contention.

For user faults, additionally restrict that show_pte() is called only
when the addr is a user-space address (addr < TASK_SIZE). This is because
the lock of tsk->mm only protects the virtual memory of user address space,
furthermore, dumping the page tables of a kernel-space address for user
faults is unnecessary and may have security implications.

Keep everything unchanged for kernel faults, because the kernel is
already in the "oops" state, acquiring a lock may risk a deadlock.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 6d021b724481fbb908eb29384898deb9f00dfe70
Version < ab14f07952adfe735d86a53518f8cd576dfd5892
Status affected
Version 6d021b724481fbb908eb29384898deb9f00dfe70
Version < 07e4d5380f2a844ab7a1b440dde350caf561cbb0
Status affected
Version 6d021b724481fbb908eb29384898deb9f00dfe70
Version < 2a14d7797a49a47bccd1a9327fd69da838dcb0dd
Status affected
Version 6d021b724481fbb908eb29384898deb9f00dfe70
Version < 63e3c958a602d0896a101a897c2361878c266ca7
Status affected
Version 6d021b724481fbb908eb29384898deb9f00dfe70
Version < 59bbf86d0ff9373bfa033ca123c1e924f09f1eba
Status affected
Version 6d021b724481fbb908eb29384898deb9f00dfe70
Version < c71f9a56520b419e55d173052629f2324deb5549
Status affected
Version 6d021b724481fbb908eb29384898deb9f00dfe70
Version < 720408d98d9fb3c91a12090436734c8c61f04545
Status affected
Version 6d021b724481fbb908eb29384898deb9f00dfe70
Version < 1039bffd6ae9c75b42b7d148d6c1106134107b66
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.0
Status affected
Version 0
Version < 4.0
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ab14f07952adfe735d86a53518f8cd576dfd5892
https://git.kernel.org/stable/c/07e4d5380f2a844ab7a1b440dde350caf561cbb0
https://git.kernel.org/stable/c/2a14d7797a49a47bccd1a9327fd69da838dcb0dd
https://git.kernel.org/stable/c/63e3c958a602d0896a101a897c2361878c266ca7
https://git.kernel.org/stable/c/59bbf86d0ff9373bfa033ca123c1e924f09f1eba
https://git.kernel.org/stable/c/c71f9a56520b419e55d173052629f2324deb5549
https://git.kernel.org/stable/c/720408d98d9fb3c91a12090436734c8c61f04545
https://git.kernel.org/stable/c/1039bffd6ae9c75b42b7d148d6c1106134107b66