← All Advisories

CVE-2026-90044

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-90044

Key Details

CVECVE-2026-90044
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-28
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_fs: Fix Use-After-Free in AIO error path

In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io()

fails with an error other than -EIOCBQUEUED, the io_data structure (`p`) is

freed. However, for AIO operations, the kiocb cancel function was already

armed and kiocb->private was set to `p`.

If a concurrent cancel operation (such as sys_io_cancel()) executes after

ffs_epfile_io() fails but before the function frees `p`, a Use-After-Free

can occur when the cancellation handler accesses the freed pointer.

To securely fix this race condition, we must properly un-arm the

cancellation. Invoking `kiocb->ki_complete()` does exactly this by

acquiring `ctx->ctx_lock` and safely removing the kiocb from the active

sequence. In doing so, it ensures that a parallel io_cancel can no longer

discover the kiocb, effectively closing the race window.

We then return -EIOCBQUEUED to notify the VFS layer that the kiocb has been

consumed and it should avoid attempting to complete the request again or

triggering subsequent completion handlers. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90044
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90044