Description
In the Linux kernel, the following vulnerability has been resolved:

firmware_loader: do not queue completed sysfs fallback requests

fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to
pending_fw_head. device_add() publishes the fallback loading interface, so
a userspace helper which discovers the device by scanning sysfs can write 0
to the loading attribute and complete the request before it is queued as
pending.

In that interleaving firmware_loading_store() calls fw_state_done() while
pending_list still points to itself, so it cannot remove an entry from
pending_fw_head. The subsequent unconditional list_add() then queues an
already-completed fw_priv. Once the request is released, pending_fw_head
can retain a pointer to freed memory and the next fallback request can
fault while validating the list.

Only in-flight fallback requests need suspend or reboot abort handling. If
the request is already DONE after device_add(), return success from the
fallback path without sending another uevent, waiting again, or queueing it
as pending. This preserves the invariant that pending_fw_head contains only
active fallback requests.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Local Use‑After‑Free that can lead to kernel crash or privilege escalation
Action: Update Kernel
AI Analysis

Impact

The kernel’s firmware_loader subsystem contains a race condition where a completed sysfs fallback request can be added twice to the pending list. A userspace helper that writes to the "loading" attribute can trigger a use‑after‑free, causing the kernel to dereference freed memory during list validation. The flaw does not provide direct code execution but can corrupt kernel memory, potentially leading to a crash or exploitation of other kernel vulnerabilities to gain higher privileges.

Affected Systems

All versions of the Linux kernel released before the corresponding patch are affected. The vulnerability is present at the kernel level and applies to every distribution that ships the unpatched kernel in its default configuration.

Risk and Exploitability

The EPSS score is less than 1% and the flaw is not listed in the CISA KEV catalog, indicating a very low likelihood of widespread exploitation. However, because the flaw is a local use‑after‑free in a privileged subsystem, a local attacker with write access to /sys/class/firmware_loading can trigger the race condition. If the attacker can also trigger a subsequent vulnerability that is dependent on corrupted memory, privilege escalation or denial of service could result. The attack vector is local system access; remote exploitation is not supported by the current description.

Generated by OpenCVE AI on September 19, 2026 at 14:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that includes the firmware_loader fix.
  • If upgrading immediately is not possible, configure the kernel to disable the sysfs fallback mechanism for firmware loading (e.g., by using a configuration option or disabling writes to /sys/class/firmware_loading).
  • Continuously monitor /sys/class/firmware_loading for abnormal write activity and audit sysfs events for unwanted firmware completion requests.

Generated by OpenCVE AI on September 19, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: firmware_loader: do not queue completed sysfs fallback requests fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to pending_fw_head. device_add() publishes the fallback loading interface, so a userspace helper which discovers the device by scanning sysfs can write 0 to the loading attribute and complete the request before it is queued as pending. In that interleaving firmware_loading_store() calls fw_state_done() while pending_list still points to itself, so it cannot remove an entry from pending_fw_head. The subsequent unconditional list_add() then queues an already-completed fw_priv. Once the request is released, pending_fw_head can retain a pointer to freed memory and the next fallback request can fault while validating the list. Only in-flight fallback requests need suspend or reboot abort handling. If the request is already DONE after device_add(), return success from the fallback path without sending another uevent, waiting again, or queueing it as pending. This preserves the invariant that pending_fw_head contains only active fallback requests.
Title firmware_loader: do not queue completed sysfs fallback requests
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:13.993Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90284

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:25.203

Modified: 2026-09-17T17:17:25.203

Link: CVE-2026-90284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:45:14Z

Weaknesses