« Volver al listado

CVE-2026-90139

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

fuse: check for NULL root inode in fuse_fill_super_submount

fuse_iget() can return NULL when its inode allocation fails, but fuse_fill_super_submount() passed the result straight to get_fuse_inode() and decremented fi->nlookup without checking it:

Inside fuse_iget() the inode allocation can fail and return NULL. The submount root takes the iget5_locked() path, whose alloc_inode() can fail under memory pressure (the auto-submount branch can fail the same way in new_inode() or fuse_alloc_submount_lookup()):

A NULL root makes get_fuse_inode() a container_of() on NULL and the nlookup decrement a write to a bogus address, oopsing the mount.

Leer descripción completaMostrar menos

With CONFIG_KASAN the following null pointer dereference is reported when the root inode allocation of an auto-submount fails (e.g. under memory pressure):

Return -ENOMEM instead; the caller tears down the partially built superblock on error, matching the other error returns in this function.

Detalles técnicos trazas, registros y código del informe original
        root = fuse_iget(sb, parent_fi->nodeid, ...);
        fi = get_fuse_inode(root);
        fi->nlookup--;

        inode = iget5_locked(sb, nodeid, fuse_inode_eq, fuse_inode_set,
                             &nodeid);
        if (!inode)
                return NULL;

==================================================================
BUG: KASAN: null-ptr-deref in fuse_get_tree_submount+0x656/0x8b0
Read of size 8 at addr 00000000000002b0 by task ls/942
CPU: 0 PID: 942 Comm: ls Tainted: G W 6.6 #15
Call Trace:
 <TASK>
 fuse_get_tree_submount+0x656/0x8b0
 vfs_get_tree+0x48/0x140
 fc_mount+0x13/0x50
 fuse_dentry_automount+0x7a/0xb0
 __traverse_mounts+0xca/0x330
 step_into+0x339/0xac0
 path_lookupat+0xc5/0x2f0
 filename_lookup+0x163/0x2a0
 vfs_statx+0xd5/0x200
 do_statx+0x83/0xd0
 __x64_sys_statx+0xa0/0xc0
 do_syscall_64+0x37/0x90
 entry_SYSCALL_64_after_hwframe+0x78/0xe2
 </TASK>
==================================================================

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90139",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
              "lessThan": "17120c5bfb16808509ea18d7fab6027802d93eba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
              "lessThan": "e0b7f2922f6bd4c23cbddb7d1fc2bada570d27d1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
              "lessThan": "a5129155ca9fba40d77ff19ffead8244e88d6f9c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
              "lessThan": "509f4a09bae7f03c87f67f053648874a5e177867",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
              "lessThan": "928f659a3e3650978a5b4829cc982324f72b474b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/fuse/inode.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/fuse/inode.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:06.523",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/17120c5bfb16808509ea18d7fab6027802d93eba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/509f4a09bae7f03c87f67f053648874a5e177867",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/928f659a3e3650978a5b4829cc982324f72b474b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a5129155ca9fba40d77ff19ffead8244e88d6f9c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e0b7f2922f6bd4c23cbddb7d1fc2bada570d27d1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: check for NULL root inode in fuse_fill_super_submount\n\nfuse_iget() can return NULL when its inode allocation fails, but\nfuse_fill_super_submount() passed the result straight to get_fuse_inode()\nand decremented fi->nlookup without checking it:\n\n        root = fuse_iget(sb, parent_fi->nodeid, ...);\n        fi = get_fuse_inode(root);\n        fi->nlookup--;\n\nInside fuse_iget() the inode allocation can fail and return NULL.  The\nsubmount root takes the iget5_locked() path, whose alloc_inode() can fail\nunder memory pressure (the auto-submount branch can fail the same way in\nnew_inode() or fuse_alloc_submount_lookup()):\n\n        inode = iget5_locked(sb, nodeid, fuse_inode_eq, fuse_inode_set,\n                             &nodeid);\n        if (!inode)\n                return NULL;\n\nA NULL root makes get_fuse_inode() a container_of() on NULL and the\nnlookup decrement a write to a bogus address, oopsing the mount.  With\nCONFIG_KASAN the following null pointer dereference is reported when the\nroot inode allocation of an auto-submount fails (e.g. under memory\npressure):\n\n==================================================================\nBUG: KASAN: null-ptr-deref in fuse_get_tree_submount+0x656/0x8b0\nRead of size 8 at addr 00000000000002b0 by task ls/942\nCPU: 0 PID: 942 Comm: ls Tainted: G W 6.6 #15\nCall Trace:\n <TASK>\n fuse_get_tree_submount+0x656/0x8b0\n vfs_get_tree+0x48/0x140\n fc_mount+0x13/0x50\n fuse_dentry_automount+0x7a/0xb0\n __traverse_mounts+0xca/0x330\n step_into+0x339/0xac0\n path_lookupat+0xc5/0x2f0\n filename_lookup+0x163/0x2a0\n vfs_statx+0xd5/0x200\n do_statx+0x83/0xd0\n __x64_sys_statx+0xa0/0xc0\n do_syscall_64+0x37/0x90\n entry_SYSCALL_64_after_hwframe+0x78/0xe2\n </TASK>\n==================================================================\n\nReturn -ENOMEM instead; the caller tears down the partially built\nsuperblock on error, matching the other error returns in this\nfunction."
    }
  ],
  "lastModified": "2026-09-17T17:17:06.523",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}