« Volver al listado

CVE-2026-90303

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults

When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set, a user fault may trigger show_pte() without any lock. If another thread in the same process concurrently calls munmap(), the page table pages may be freed while show_pte() is still traversing them, causing a use-after-free in show_pte().

If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table of PMD are freed when show_pte() is running.

Acquire mmap_write_lock() around show_pte() for user faults to fix the contention.

Leer descripción completaMostrar menos

For user faults, additionally restrict that show_pte() is called only when the addr is a user-space address (addr < TASK_SIZE). This is because the lock of tsk->mm only protects the virtual memory of user address space, furthermore, dumping the page tables of a kernel-space address for user faults is unnecessary and may have security implications.

Keep everything unchanged for kernel faults, because the kernel is already in the "oops" state, acquiring a lock may risk a deadlock.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90303",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6d021b724481fbb908eb29384898deb9f00dfe70",
              "lessThan": "ab14f07952adfe735d86a53518f8cd576dfd5892",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6d021b724481fbb908eb29384898deb9f00dfe70",
              "lessThan": "07e4d5380f2a844ab7a1b440dde350caf561cbb0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6d021b724481fbb908eb29384898deb9f00dfe70",
              "lessThan": "2a14d7797a49a47bccd1a9327fd69da838dcb0dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6d021b724481fbb908eb29384898deb9f00dfe70",
              "lessThan": "63e3c958a602d0896a101a897c2361878c266ca7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6d021b724481fbb908eb29384898deb9f00dfe70",
              "lessThan": "59bbf86d0ff9373bfa033ca123c1e924f09f1eba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6d021b724481fbb908eb29384898deb9f00dfe70",
              "lessThan": "c71f9a56520b419e55d173052629f2324deb5549",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6d021b724481fbb908eb29384898deb9f00dfe70",
              "lessThan": "720408d98d9fb3c91a12090436734c8c61f04545",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6d021b724481fbb908eb29384898deb9f00dfe70",
              "lessThan": "1039bffd6ae9c75b42b7d148d6c1106134107b66",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm/mm/fault.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm/mm/fault.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:27.887",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/07e4d5380f2a844ab7a1b440dde350caf561cbb0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1039bffd6ae9c75b42b7d148d6c1106134107b66",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2a14d7797a49a47bccd1a9327fd69da838dcb0dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/59bbf86d0ff9373bfa033ca123c1e924f09f1eba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/63e3c958a602d0896a101a897c2361878c266ca7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/720408d98d9fb3c91a12090436734c8c61f04545",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab14f07952adfe735d86a53518f8cd576dfd5892",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c71f9a56520b419e55d173052629f2324deb5549",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults\n\nWhen CONFIG_DEBUG_USER=y, and cmdline \"user_debug=31\" is set,\na user fault may trigger show_pte() without any lock.\nIf another thread in the same process concurrently calls munmap(),\nthe page table pages may be freed while show_pte() is still traversing\nthem, causing a use-after-free in show_pte().\n\nIf CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table\nof PMD are freed when show_pte() is running.\n\nAcquire mmap_write_lock() around show_pte() for user faults to fix the\ncontention.\n\nFor user faults, additionally restrict that show_pte() is called only\nwhen the addr is a user-space address (addr < TASK_SIZE). This is because\nthe lock of tsk->mm only protects the virtual memory of user address space,\nfurthermore, dumping the page tables of a kernel-space address for user\nfaults is unnecessary and may have security implications.\n\nKeep everything unchanged for kernel faults, because the kernel is\nalready in the \"oops\" state, acquiring a lock may risk a deadlock."
    }
  ],
  "lastModified": "2026-09-17T17:17:27.887",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}