Description
In the Linux kernel, the following vulnerability has been resolved:

rapidio: clear mport->net when rio_add_net() fails

rio_alloc_net() stores the newly allocated rio_net in mport->net before
rio_scan_alloc_net() registers the device.

If rio_add_net() fails, rio_scan_alloc_net() drops the device reference
with put_device(), which releases the rio_net through the device release
callback. However, mport->net is left pointing at the freed object.

A later mport unregister path can then dereference the dangling mport->net
pointer and may try to free the same rio_net again.

Clear mport->net in the rio_add_net() failure path, matching the cleanup
done for the destID table allocation failure path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in rapidio driver leading to possible kernel crash and denial of service
Action: Update Kernel
AI Analysis

Impact

The rapidio driver in the Linux kernel stores a newly allocated rio_net in mport->net before registering the device. If rio_add_net() fails, the device reference is released, but mport->net continues to point at the freed object. A later mport unregister path can dereference this dangling pointer and attempt to free the same rio_net again, resulting in a use‑after‑free that can crash the kernel and cause denial of service. This flaw primarily impacts availability; the advisory does not indicate that privilege escalation is possible.

Affected Systems

All Linux kernel releases that include the rapidio driver without the patch identified in the referenced commits. The specific vendor is Linux and the product is the Linux Kernel; version information is not explicitly provided in the advisory, implying that any kernel prior to the fix is affected.

Risk and Exploitability

The EPSS score is under 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The bug is a kernel use‑after‑free; an attacker would need local system access to trigger the failure and subsequent unregistration. Because the flaw lives in kernel space, the most likely impact is a system crash or denial of service. The overall risk is low to moderate and is chiefly local.

Generated by OpenCVE AI on September 19, 2026 at 14:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the rapidio patch detailed in the linked commits.
  • If an immediate kernel upgrade is not possible, restrict or disable the rapidio driver on systems where the flaw could be exploited, or prevent its unregistration until a patch is applied.
  • Monitor system logs for rapidio driver failures or kernel panics and schedule a reboot if a crash occurs as a temporary mitigation while awaiting a patch.

Generated by OpenCVE AI on September 19, 2026 at 14:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: rapidio: clear mport->net when rio_add_net() fails rio_alloc_net() stores the newly allocated rio_net in mport->net before rio_scan_alloc_net() registers the device. If rio_add_net() fails, rio_scan_alloc_net() drops the device reference with put_device(), which releases the rio_net through the device release callback. However, mport->net is left pointing at the freed object. A later mport unregister path can then dereference the dangling mport->net pointer and may try to free the same rio_net again. Clear mport->net in the rio_add_net() failure path, matching the cleanup done for the destID table allocation failure path.
Title rapidio: clear mport->net when rio_add_net() fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:36.840Z

Reserved: 2026-09-11T19:38:34.801Z

Link: CVE-2026-90319

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:29.817

Modified: 2026-09-17T17:17:29.817

Link: CVE-2026-90319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:45:14Z

Weaknesses