Description
In the Linux kernel, the following vulnerability has been resolved:

rust: devres: fix race between concurrent revokers

There is a potential race condition when two paths try to revoke a
Devres concurrently.

The driver core's devres_release_all() calls Revocable::revoke() via the
release callback, while Devres::drop() calls revoke_nosync() on another
CPU.

The revoker that does not claim the is_available swap returns
immediately, but the revoker that did may still be executing
drop_in_place() on the inner data. This can cause a use-after-free when
the other revoker's caller proceeds to drop adjacent resources that
drop_in_place() still references (e.g., Devres<DmaMappedSgt> racing with
SGTable freeing the backing sg_table and pages).

Fix this by adding a Completion. The release callback signals the
Completion after revoke() finishes, and Devres::drop() waits for it when
it loses the is_available swap. This ensures the wrapped object is fully
torn down before Devres::drop() returns.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free leading to memory corruption and potential system instability
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, a race condition in the Rust‑based devres module allows two concurrent revoker paths to interleave. The revocation performed by devres_release_all() via the release callback can occur at the same time as the drop logic executed on another CPU. If the revoker that does not claim the is_available swap returns immediately while the other is still running drop_in_place() on the inner data, a use‑after‑free can occur when a caller proceeds to drop adjacent resources that are still referenced. This bug is classified as CWE‑825. The resulting memory corruption can lead to kernel crashes or unstable behavior; the CVE description does not assert that arbitrary code execution is possible.

Affected Systems

Any Linux kernel that includes the Rust‑based devres implementation, particularly when devres_release_all() and Devres<DmaMappedSgt> or SGTable are compiled; all distributions shipping the current code path are affected.

Risk and Exploitability

The CVSS score is 7.8 and the EPSS score is below 1 %, indicating a low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. Attackers would need to cause concurrent revocation on separate CPUs, a scenario that is plausible. The use‑after‑free could lead to memory corruption or system crash. The exact attack vector is not explicitly described, but it is inferred that concurrent revocations on different CPUs, such as simultaneous driver unloads, could trigger the race.

Generated by OpenCVE AI on September 15, 2026 at 19:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch commit acc516dfa1972d31836b50abc0115216cd0fccc5, which introduces a Completion synchronization to prevent the concurrent revoker race.
  • If a vendor does not provide an immediate patch, rebuild or update the kernel with the latest Rust devres module that includes the fix.
  • Review and, if possible, remove or limit drivers that rely heavily on devres_release_all() during unload or shutdown to reduce concurrent revocation scenarios.

Generated by OpenCVE AI on September 15, 2026 at 19:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: rust: devres: fix race between concurrent revokers There is a potential race condition when two paths try to revoke a Devres concurrently. The driver core's devres_release_all() calls Revocable::revoke() via the release callback, while Devres::drop() calls revoke_nosync() on another CPU. The revoker that does not claim the is_available swap returns immediately, but the revoker that did may still be executing drop_in_place() on the inner data. This can cause a use-after-free when the other revoker's caller proceeds to drop adjacent resources that drop_in_place() still references (e.g., Devres<DmaMappedSgt> racing with SGTable freeing the backing sg_table and pages). Fix this by adding a Completion. The release callback signals the Completion after revoke() finishes, and Devres::drop() waits for it when it loses the is_available swap. This ensures the wrapped object is fully torn down before Devres::drop() returns.
Title rust: devres: fix race between concurrent revokers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:34:08.821Z

Reserved: 2026-09-11T19:38:34.764Z

Link: CVE-2026-89764

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:07.637

Modified: 2026-09-13T07:17:40.843

Link: CVE-2026-89764

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:47:05Z

Links: CVE-2026-89764 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference