Description
In the Linux kernel, the following vulnerability has been resolved:

module/dups: Fix use-after-free in kmod_dup_req lifetime handling

The kmod dups code uses RCU to ensure that a kmod_dup_req instance is freed
only after it is no longer referenced. When releasing an instance, the
kmod_dup_request_delete() function removes the kmod_dup_req from the
dup_kmod_reqs list, waits via synchronize_rcu() and finally frees it.
However, this doesn't work correctly because parallel users referencing the
instance in kmod_dup_request_exists_wait() don't enter an RCU read-side
critical section. This can result in a use-after-free.

The kmod_dup_request_exists_wait() function may need to hold a valid
reference to a kmod_dup_req instance across a blocking wait until the
corresponding modprobe command completes. This makes it unsuitable for RCU.

Fix the issue by changing the lifecycle management of kmod_dup_req to use
reference counting.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption with potential privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free in the Linux kernel’s kmod duplicate request handling. The bug occurs when a kmod_dup_req instance is freed before all references are released because the code incorrectly uses RCU. An attacker could trigger this flaw to corrupt kernel memory, possibly gaining elevated privileges or crashing the system. The weakness is a classic use‑after‑free, which can lead to arbitrary code execution at kernel level. The explicit attack vector is not stated; based on the description, it is inferred that local exploitation via a malicious module load request on a system running the vulnerable kernel is possible. The description does not specify how an attacker could trigger the flaw, so the attack vector is inferred rather than confirmed.

Affected Systems

All Linux kernel builds that contain the kmod/dups implementation before the advertised commit are potentially affected. The CVE references multiple kernel git patches; regardless of the exact kernel version, any system running a kernel that has not been updated to include the reference‑counting fix is at risk. Specific kernel versions are not enumerated in the data, so it is inferred that any build preceding the commit that adds reference counting remains vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. EPSS is less than 1%, showing low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the failure occurs in kernel space, so local or physical attackers can potentially exploit the flaw. An exploit would require triggering the freed object, which may involve submitting a malformed module load request or similar. Since the issue is not tied to user‑space privileges, the risk remains high for any system where kernel developers rely on the duplicated module logic. The CVE does not provide a known exploit; the low EPSS indicates that exploitation is unlikely at present. The risk assessment infers that a local or physical attacker could potentially exploit the flaw, but the exact feasibility remains uncertain.

Generated by OpenCVE AI on September 20, 2026 at 00:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that incorporates the kmod/dups commit referenced in the CVE documentation.
  • Reboot the system to load the updated kernel and ensure the affected module code is not present.
  • If using custom or third‑party kernel modules that interact with kmod_dup_req, rebuild them against the updated kernel headers to enforce the new reference‑counting mechanism.

Generated by OpenCVE AI on September 20, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: module/dups: Fix use-after-free in kmod_dup_req lifetime handling The kmod dups code uses RCU to ensure that a kmod_dup_req instance is freed only after it is no longer referenced. When releasing an instance, the kmod_dup_request_delete() function removes the kmod_dup_req from the dup_kmod_reqs list, waits via synchronize_rcu() and finally frees it. However, this doesn't work correctly because parallel users referencing the instance in kmod_dup_request_exists_wait() don't enter an RCU read-side critical section. This can result in a use-after-free. The kmod_dup_request_exists_wait() function may need to hold a valid reference to a kmod_dup_req instance across a blocking wait until the corresponding modprobe command completes. This makes it unsuitable for RCU. Fix the issue by changing the lifecycle management of kmod_dup_req to use reference counting.
Title module/dups: Fix use-after-free in kmod_dup_req lifetime handling
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:20.524Z

Reserved: 2026-09-11T19:38:34.798Z

Link: CVE-2026-90291

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:26.263

Modified: 2026-09-18T18:17:52.007

Link: CVE-2026-90291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:13Z

Weaknesses