CVE-2026-90140
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-90140, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-17

Last updated on: 2026-09-17

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: cuse: wait for pending RCU callbacks on module exit Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"), fuse_conn_put() frees the fuse_conn through call_rcu() rather than synchronously. For cuse, fc->release is cuse_fc_release(), which lives in the cuse module. If the module is removed before the RCU grace period ends, the callback jumps into freed module memory: userspace / module unload | RCU softirq ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ close(/dev/cuse) | cuse_channel_release() | fuse_dev_release() | fuse_conn_put(fch->conn) | call_rcu(delayed_release) ------+---> callback queued | rmmod cuse | cuse_exit() | cuse_channel_destroy() | ... | return | | <module text freed> | | rcu_do_batch() | delayed_release() | fc->release() | -> cuse_fc_release() | ^^^ freed text! The freed module text is unmapped by vfree(), so the jump into the stale callback triggers a page-fault Oops. If the virtual address is subsequently reused, the callback could execute unrelated code (undefined behaviour). Fix this by calling rcu_barrier() in cuse_exit() so that any pending fuse_conn release callback completes before the module is removed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-17
Last Modified
2026-09-17
Generated
2026-10-10
EPSS Evaluated
2026-10-09
NVD

Affected Vendors & Products

Showing 11 associated CPEs
Vendor Product Version / Range
Linux Linux bfbab62ca69f72bcd14ea30de1fb98f6080ad464
Linux Linux a8f650b93e55764ca9ff8e1ddebc151f57024086
Linux Linux 535e9bd0e8f8d8cfdc29de7cdb902b5041427fe6
Linux Linux 053fc4f755ad43cf35210677bcba798ccdc48d0c
Linux Linux 053fc4f755ad43cf35210677bcba798ccdc48d0c
Linux Linux 053fc4f755ad43cf35210677bcba798ccdc48d0c
Linux Linux 053fc4f755ad43cf35210677bcba798ccdc48d0c
Linux Linux 5.15.166
Linux Linux 6.1.107
Linux Linux 6.6.48
Linux Linux 6.8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90140. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart