Description
In the Linux kernel, the following vulnerability has been resolved:

PCI: Fix UAF when probe runs concurrent to dyn ID removal

Dynamic IDs are only guaranteed to be valid when dynids.lock is held,
as remove_id_store() can free the node. Thus, make a copy in
pci_match_device(). Also, clarify that the id parameter is only valid
during probe.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Patch Immediately
AI Analysis

Impact

The Linux kernel contains a use‑after‑free flaw that occurs when a PCI device probe runs concurrently with the removal of a dynamic ID. The bug is caused by dynamic IDs being freed while still referenced in pci_match_device unless dynids.lock is held. An attacker who can influence the order of probing could trigger the freed memory to be accessed, leading to memory corruption or execution of malicious code within the kernel, potentially allowing local privilege escalation or denial of service.

Affected Systems

All versions of the Linux kernel that do not include the recent patch are affected. No specific version range is listed, meaning any kernel image prior to the fix is vulnerable.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a very low projected exploitation likelihood at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit has been documented. The attack requires a local vector, typically through crafted PCI device enrollment during system initialization or device hot‑plug events, and therefore would likely be limited to systems where the attacker can introduce or manipulate PCI hardware. Based on the description, it is inferred that an attacker would need local access or the ability to control the PCI probing process to exploit this flaw.

Generated by OpenCVE AI on September 19, 2026 at 12:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the fix that copies dynamic IDs in pci_match_device
  • If an immediate kernel upgrade is not possible, apply any vendor‑specific backports or security patches that address the use‑after‑free in PCI handling before a full kernel replacement is available
  • If hot‑plug PCI devices are not required, disable them via BIOS/UEFI configuration to reduce exploitable enumeration timing.

Generated by OpenCVE AI on September 19, 2026 at 12:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: PCI: Fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only guaranteed to be valid when dynids.lock is held, as remove_id_store() can free the node. Thus, make a copy in pci_match_device(). Also, clarify that the id parameter is only valid during probe.
Title PCI: Fix UAF when probe runs concurrent to dyn ID removal
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:45.185Z

Reserved: 2026-09-11T19:38:34.814Z

Link: CVE-2026-90421

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:46.623

Modified: 2026-09-17T17:17:46.623

Link: CVE-2026-90421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:00:12Z

Weaknesses