CVE-2026-90139
In the Linux kernel, the following vulnerability has been resolved:
fuse: check for NULL root inode in fuse_fill_super_submount
fuse_iget() can return NULL when its inode allocation fails, but fuse_fill_super_submount() passed the result straight to get_fuse_inode() and decremented fi->nlookup without checking it:
Inside fuse_iget() the inode allocation can fail and return NULL. The submount root takes the iget5_locked() path, whose alloc_inode() can fail under memory pressure (the auto-submount branch can fail the same way in new_inode() or fuse_alloc_submount_lookup()):
A NULL root makes get_fuse_inode() a container_of() on NULL and the nlookup decrement a write to a bogus address, oopsing the mount.
Leer descripción completaMostrar menos
With CONFIG_KASAN the following null pointer dereference is reported when the root inode allocation of an auto-submount fails (e.g. under memory pressure):
Return -ENOMEM instead; the caller tears down the partially built superblock on error, matching the other error returns in this function.
Detalles técnicos trazas, registros y código del informe original
root = fuse_iget(sb, parent_fi->nodeid, ...);
fi = get_fuse_inode(root);
fi->nlookup--;
inode = iget5_locked(sb, nodeid, fuse_inode_eq, fuse_inode_set,
&nodeid);
if (!inode)
return NULL;
==================================================================
BUG: KASAN: null-ptr-deref in fuse_get_tree_submount+0x656/0x8b0
Read of size 8 at addr 00000000000002b0 by task ls/942
CPU: 0 PID: 942 Comm: ls Tainted: G W 6.6 #15
Call Trace:
<TASK>
fuse_get_tree_submount+0x656/0x8b0
vfs_get_tree+0x48/0x140
fc_mount+0x13/0x50
fuse_dentry_automount+0x7a/0xb0
__traverse_mounts+0xca/0x330
step_into+0x339/0xac0
path_lookupat+0xc5/0x2f0
filename_lookup+0x163/0x2a0
vfs_statx+0xd5/0x200
do_statx+0x83/0xd0
__x64_sys_statx+0xa0/0xc0
do_syscall_64+0x37/0x90
entry_SYSCALL_64_after_hwframe+0x78/0xe2
</TASK>
==================================================================CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/17120c5bfb16808509ea18d7fab6027802d93eba
- https://git.kernel.org/stable/c/509f4a09bae7f03c87f67f053648874a5e177867
- https://git.kernel.org/stable/c/928f659a3e3650978a5b4829cc982324f72b474b
- https://git.kernel.org/stable/c/a5129155ca9fba40d77ff19ffead8244e88d6f9c
- https://git.kernel.org/stable/c/e0b7f2922f6bd4c23cbddb7d1fc2bada570d27d1
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90139",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
"lessThan": "17120c5bfb16808509ea18d7fab6027802d93eba",
"versionType": "git"
},
{
"status": "affected",
"version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
"lessThan": "e0b7f2922f6bd4c23cbddb7d1fc2bada570d27d1",
"versionType": "git"
},
{
"status": "affected",
"version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
"lessThan": "a5129155ca9fba40d77ff19ffead8244e88d6f9c",
"versionType": "git"
},
{
"status": "affected",
"version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
"lessThan": "509f4a09bae7f03c87f67f053648874a5e177867",
"versionType": "git"
},
{
"status": "affected",
"version": "1866d779d5d2abae59d304e809600ca3ca8d0071",
"lessThan": "928f659a3e3650978a5b4829cc982324f72b474b",
"versionType": "git"
}
],
"programFiles": [
"fs/fuse/inode.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/fuse/inode.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:06.523",
"references": [
{
"url": "https://git.kernel.org/stable/c/17120c5bfb16808509ea18d7fab6027802d93eba",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/509f4a09bae7f03c87f67f053648874a5e177867",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/928f659a3e3650978a5b4829cc982324f72b474b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a5129155ca9fba40d77ff19ffead8244e88d6f9c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e0b7f2922f6bd4c23cbddb7d1fc2bada570d27d1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: check for NULL root inode in fuse_fill_super_submount\n\nfuse_iget() can return NULL when its inode allocation fails, but\nfuse_fill_super_submount() passed the result straight to get_fuse_inode()\nand decremented fi->nlookup without checking it:\n\n root = fuse_iget(sb, parent_fi->nodeid, ...);\n fi = get_fuse_inode(root);\n fi->nlookup--;\n\nInside fuse_iget() the inode allocation can fail and return NULL. The\nsubmount root takes the iget5_locked() path, whose alloc_inode() can fail\nunder memory pressure (the auto-submount branch can fail the same way in\nnew_inode() or fuse_alloc_submount_lookup()):\n\n inode = iget5_locked(sb, nodeid, fuse_inode_eq, fuse_inode_set,\n &nodeid);\n if (!inode)\n return NULL;\n\nA NULL root makes get_fuse_inode() a container_of() on NULL and the\nnlookup decrement a write to a bogus address, oopsing the mount. With\nCONFIG_KASAN the following null pointer dereference is reported when the\nroot inode allocation of an auto-submount fails (e.g. under memory\npressure):\n\n==================================================================\nBUG: KASAN: null-ptr-deref in fuse_get_tree_submount+0x656/0x8b0\nRead of size 8 at addr 00000000000002b0 by task ls/942\nCPU: 0 PID: 942 Comm: ls Tainted: G W 6.6 #15\nCall Trace:\n <TASK>\n fuse_get_tree_submount+0x656/0x8b0\n vfs_get_tree+0x48/0x140\n fc_mount+0x13/0x50\n fuse_dentry_automount+0x7a/0xb0\n __traverse_mounts+0xca/0x330\n step_into+0x339/0xac0\n path_lookupat+0xc5/0x2f0\n filename_lookup+0x163/0x2a0\n vfs_statx+0xd5/0x200\n do_statx+0x83/0xd0\n __x64_sys_statx+0xa0/0xc0\n do_syscall_64+0x37/0x90\n entry_SYSCALL_64_after_hwframe+0x78/0xe2\n </TASK>\n==================================================================\n\nReturn -ENOMEM instead; the caller tears down the partially built\nsuperblock on error, matching the other error returns in this\nfunction."
}
],
"lastModified": "2026-09-17T17:17:06.523",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}