Description
In the Linux kernel, the following vulnerability has been resolved:

liveupdate: Remember FLB retrieve() status

LUO keeps track of successful retrieve attempts on an FLB. It does so
to avoid multiple retrievals of the same FLB. Multiple retrievals cause
problems because once the FLB is retrieved, the serialized data
structures are likely freed and the FLB is likely in a very different
state from what the code expects.

All this works well when retrieve succeeds. When it fails,
luo_flb_retrieve_one() returns the error immediately, without ever
storing anywhere that a retrieve was attempted or what its error code
was. If the user attempts to retrieve another file registered with the
same FLB, LUO will attempt to call the FLB's retrieve() callback again.

The retry is problematic for much of the same reasons listed above. The
FLB is likely in a very different state than what the retrieve logic
normally expects (e.g. some KHO pages may have already been restored and
freed).

There is no sane way of attempting the retrieve again. Remember the
error retrieve returned and directly return it on a retry.

This is done by changing the retrieved bool to a retrieve_status
integer. A value of 0 means retrieve was never attempted, a positive
value means it succeeded, and a negative value means it failed and the
error code is the value.

This is similar to commit f85b1c6af5bc ("liveupdate: luo_file: remember
retrieve() status") which did the same for LUO files.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The flaw in the Linux kernel’s liveupdate subsystem stems from incomplete state tracking when a firmware load block (FLB) retrieval fails. The system does not record a failed attempt, so a subsequent retrieval is retried without knowledge that the FLB instance is already in an altered or freed state. This can cause the kernel to invoke the retrieve callback on an invalid or already restored data structure, potentially leading to a kernel panic or other undefined behavior that disables the host. The weakness is a classic example of improper handling of function return values and a use‑after‑free scenario.

Affected Systems

Linux kernel installations are impacted. The vulnerability is present in all kernel releases prior to the commit that introduced the retrieval status tracking, identified by the references in the advisory. Specific version numbers are not listed, so any kernel older than the patched release should be considered vulnerable.

Risk and Exploitability

The exploitability of this defect is low, as indicated by an EPSS score of less than 1% and the absence from the CISA KEV catalog. The required conditions for successful exploitation include the ability to trigger a liveupdate retrieval operation, which typically demands elevated privileges or an existing kernel code execution vector. Once triggered, the bug can force a kernel crash, resulting in a denial of service that requires a system reboot.

Generated by OpenCVE AI on September 19, 2026 at 05:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the liveupdate retrieval status fix, such as the commit identified in the advisory references.
  • Reboot the system after applying the update and verify that liveupdate operations no longer retry failures.
  • After upgrading, monitor system logs for any remaining liveupdate retry attempts and validate overall kernel stability.

Generated by OpenCVE AI on September 19, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Linux kernel
Vendors & Products Linux kernel

Sat, 19 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-686

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: liveupdate: Remember FLB retrieve() status LUO keeps track of successful retrieve attempts on an FLB. It does so to avoid multiple retrievals of the same FLB. Multiple retrievals cause problems because once the FLB is retrieved, the serialized data structures are likely freed and the FLB is likely in a very different state from what the code expects. All this works well when retrieve succeeds. When it fails, luo_flb_retrieve_one() returns the error immediately, without ever storing anywhere that a retrieve was attempted or what its error code was. If the user attempts to retrieve another file registered with the same FLB, LUO will attempt to call the FLB's retrieve() callback again. The retry is problematic for much of the same reasons listed above. The FLB is likely in a very different state than what the retrieve logic normally expects (e.g. some KHO pages may have already been restored and freed). There is no sane way of attempting the retrieve again. Remember the error retrieve returned and directly return it on a retry. This is done by changing the retrieved bool to a retrieve_status integer. A value of 0 means retrieve was never attempted, a positive value means it succeeded, and a negative value means it failed and the error code is the value. This is similar to commit f85b1c6af5bc ("liveupdate: luo_file: remember retrieve() status") which did the same for LUO files.
Title liveupdate: Remember FLB retrieve() status
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Kernel Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:59.673Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92483

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:50.373

Modified: 2026-09-17T17:17:50.373

Link: CVE-2026-92483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:11Z

Weaknesses
  • CWE-416

    Use After Free

  • CWE-686

    Function Call With Incorrect Argument Type