CVE-2026-90284
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-90284, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-17
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: do not queue completed sysfs fallback requests
fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to
pending_fw_head. device_add() publishes the fallback loading interface, so
a userspace helper which discovers the device by scanning sysfs can write 0
to the loading attribute and complete the request before it is queued as
pending.
In that interleaving firmware_loading_store() calls fw_state_done() while
pending_list still points to itself, so it cannot remove an entry from
pending_fw_head. The subsequent unconditional list_add() then queues an
already-completed fw_priv. Once the request is released, pending_fw_head
can retain a pointer to freed memory and the next fallback request can
fault while validating the list.
Only in-flight fallback requests need suspend or reboot abort handling. If
the request is already DONE after device_add(), return success from the
fallback path without sending another uevent, waiting again, or queueing it
as pending. This preserves the invariant that pending_fw_head contains only
active fallback requests.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | ecb739cf15a9bae040ce6b60209b78b92512d120 |
| Linux | Linux | 75d95e2e39b27f733f21e6668af1c9893a97de5e |
| Linux | Linux | 75d95e2e39b27f733f21e6668af1c9893a97de5e |
| Linux | Linux | 75d95e2e39b27f733f21e6668af1c9893a97de5e |
| Linux | Linux | 75d95e2e39b27f733f21e6668af1c9893a97de5e |
| Linux | Linux | 75d95e2e39b27f733f21e6668af1c9893a97de5e |
| Linux | Linux | 75d95e2e39b27f733f21e6668af1c9893a97de5e |
| Linux | Linux | 75d95e2e39b27f733f21e6668af1c9893a97de5e |
| Linux | Linux | 67cf0fbcac0d42d4d4686cddc1e39f465bbfec37 |
| Linux | Linux | d09639528b66b5c7c20dc8f7fb8928aacabd40bb |
| Linux | Linux | c14a54675db7131791402fa22fb0fa6da1f5fb66 |
| Linux | Linux | 5.10.58 |
| Linux | Linux | 4.19.203 |
| Linux | Linux | 5.4.140 |
| Linux | Linux | 5.13.10 |
| Linux | Linux | 5.14 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |