Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_fs: Fix Use-After-Free in AIO error path

In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io()
fails with an error other than -EIOCBQUEUED, the io_data structure (`p`) is
freed. However, for AIO operations, the kiocb cancel function was already
armed and kiocb->private was set to `p`.

If a concurrent cancel operation (such as sys_io_cancel()) executes after
ffs_epfile_io() fails but before the function frees `p`, a Use-After-Free
can occur when the cancellation handler accesses the freed pointer.

To securely fix this race condition, we must properly un-arm the
cancellation. Invoking `kiocb->ki_complete()` does exactly this by
acquiring `ctx->ctx_lock` and safely removing the kiocb from the active
sequence. In doing so, it ensures that a parallel io_cancel can no longer
discover the kiocb, effectively closing the race window.

We then return -EIOCBQUEUED to notify the VFS layer that the kiocb has been
consumed and it should avoid attempting to complete the request again or
triggering subsequent completion handlers.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the ffs_epfile_write_iter and ffs_epfile_read_iter input–output functions may free an io_data structure while an AIO cancel handler still references it. When a cancellation occurs after the free but before the pointer is cleared, the cancel routine dereferences a dangling pointer, creating a use‑after‑free that can be leveraged for arbitrary code execution. The flaw is a classic use‑after‑free weakness (CWE‑416).

Affected Systems

The vulnerability affects all Linux kernel deployments that have not applied the corrective commit. No specific kernel versions are listed in the vulnerability data; any running kernel without the patch is potentially exposed.

Risk and Exploitability

The CVSS score of 7.8 classifies this as a high‑severity flaw, and the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is a local kernel race; an attacker with the ability to trigger AIO operations and cancellation on a target system could achieve privilege escalation or arbitrary code execution. The vulnerability is not present in the CISA KEV list, but the kernel nature means that any unpatched system remains a risk until the kernel is updated.

Generated by OpenCVE AI on September 18, 2026 at 05:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit fixing the use‑after‑free.
  • If an immediate kernel upgrade is not possible, restrict or disable AIO operations for untrusted processes or services to reduce the attack surface.
  • Monitor kernel logs for abnormal io_cancel activity and audit AIO usage patterns.

Generated by OpenCVE AI on September 18, 2026 at 05:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error path In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io() fails with an error other than -EIOCBQUEUED, the io_data structure (`p`) is freed. However, for AIO operations, the kiocb cancel function was already armed and kiocb->private was set to `p`. If a concurrent cancel operation (such as sys_io_cancel()) executes after ffs_epfile_io() fails but before the function frees `p`, a Use-After-Free can occur when the cancellation handler accesses the freed pointer. To securely fix this race condition, we must properly un-arm the cancellation. Invoking `kiocb->ki_complete()` does exactly this by acquiring `ctx->ctx_lock` and safely removing the kiocb from the active sequence. In doing so, it ensures that a parallel io_cancel can no longer discover the kiocb, effectively closing the race window. We then return -EIOCBQUEUED to notify the VFS layer that the kiocb has been consumed and it should avoid attempting to complete the request again or triggering subsequent completion handlers.
Title usb: gadget: f_fs: Fix Use-After-Free in AIO error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:18.248Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90044

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:17.660

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-90044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:30:04Z

Weaknesses