CVE-2026-90284
In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: do not queue completed sysfs fallback requests
fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to pending_fw_head. device_add() publishes the fallback loading interface, so a userspace helper which discovers the device by scanning sysfs can write 0 to the loading attribute and complete the request before it is queued as pending.
In that interleaving firmware_loading_store() calls fw_state_done() while pending_list still points to itself, so it cannot remove an entry from pending_fw_head.
Leer descripción completaMostrar menos
The subsequent unconditional list_add() then queues an already-completed fw_priv. Once the request is released, pending_fw_head can retain a pointer to freed memory and the next fallback request can fault while validating the list.
Only in-flight fallback requests need suspend or reboot abort handling. If the request is already DONE after device_add(), return success from the fallback path without sending another uevent, waiting again, or queueing it as pending. This preserves the invariant that pending_fw_head contains only active fallback requests.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/5a250bff75a446374c05622973b18b4ab662b504
- https://git.kernel.org/stable/c/6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b
- https://git.kernel.org/stable/c/85aeb8fc61839098ae0942ccba86e669c08e75d4
- https://git.kernel.org/stable/c/93a2385730540105df8524447dcc11309ad280f9
- https://git.kernel.org/stable/c/b48373c901951fad1a26bd7c33ad91172b3945b5
- https://git.kernel.org/stable/c/c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7
- https://git.kernel.org/stable/c/ea33fac0df7fe7b49a4b27acb83e227b82317d1d
- https://git.kernel.org/stable/c/fb4824880b0dba0e7b3a497c46c642f979630392
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90284",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ecb739cf15a9bae040ce6b60209b78b92512d120",
"lessThan": "c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7",
"versionType": "git"
},
{
"status": "affected",
"version": "75d95e2e39b27f733f21e6668af1c9893a97de5e",
"lessThan": "93a2385730540105df8524447dcc11309ad280f9",
"versionType": "git"
},
{
"status": "affected",
"version": "75d95e2e39b27f733f21e6668af1c9893a97de5e",
"lessThan": "ea33fac0df7fe7b49a4b27acb83e227b82317d1d",
"versionType": "git"
},
{
"status": "affected",
"version": "75d95e2e39b27f733f21e6668af1c9893a97de5e",
"lessThan": "5a250bff75a446374c05622973b18b4ab662b504",
"versionType": "git"
},
{
"status": "affected",
"version": "75d95e2e39b27f733f21e6668af1c9893a97de5e",
"lessThan": "85aeb8fc61839098ae0942ccba86e669c08e75d4",
"versionType": "git"
},
{
"status": "affected",
"version": "75d95e2e39b27f733f21e6668af1c9893a97de5e",
"lessThan": "6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b",
"versionType": "git"
},
{
"status": "affected",
"version": "75d95e2e39b27f733f21e6668af1c9893a97de5e",
"lessThan": "fb4824880b0dba0e7b3a497c46c642f979630392",
"versionType": "git"
},
{
"status": "affected",
"version": "75d95e2e39b27f733f21e6668af1c9893a97de5e",
"lessThan": "b48373c901951fad1a26bd7c33ad91172b3945b5",
"versionType": "git"
},
{
"status": "affected",
"version": "67cf0fbcac0d42d4d4686cddc1e39f465bbfec37",
"versionType": "git"
},
{
"status": "affected",
"version": "d09639528b66b5c7c20dc8f7fb8928aacabd40bb",
"versionType": "git"
},
{
"status": "affected",
"version": "c14a54675db7131791402fa22fb0fa6da1f5fb66",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.58",
"lessThan": "5.10.270",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.19.203",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.140",
"lessThan": "5.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.13.10",
"lessThan": "5.14",
"versionType": "semver"
}
],
"programFiles": [
"drivers/base/firmware_loader/fallback.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/base/firmware_loader/fallback.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:25.203",
"references": [
{
"url": "https://git.kernel.org/stable/c/5a250bff75a446374c05622973b18b4ab662b504",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/85aeb8fc61839098ae0942ccba86e669c08e75d4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/93a2385730540105df8524447dcc11309ad280f9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b48373c901951fad1a26bd7c33ad91172b3945b5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ea33fac0df7fe7b49a4b27acb83e227b82317d1d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fb4824880b0dba0e7b3a497c46c642f979630392",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: do not queue completed sysfs fallback requests\n\nfw_load_sysfs_fallback() calls device_add() before adding the fw_priv to\npending_fw_head. device_add() publishes the fallback loading interface, so\na userspace helper which discovers the device by scanning sysfs can write 0\nto the loading attribute and complete the request before it is queued as\npending.\n\nIn that interleaving firmware_loading_store() calls fw_state_done() while\npending_list still points to itself, so it cannot remove an entry from\npending_fw_head. The subsequent unconditional list_add() then queues an\nalready-completed fw_priv. Once the request is released, pending_fw_head\ncan retain a pointer to freed memory and the next fallback request can\nfault while validating the list.\n\nOnly in-flight fallback requests need suspend or reboot abort handling. If\nthe request is already DONE after device_add(), return success from the\nfallback path without sending another uevent, waiting again, or queueing it\nas pending. This preserves the invariant that pending_fw_head contains only\nactive fallback requests."
}
],
"lastModified": "2026-09-17T17:17:25.203",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}