CVE-2026-90284
Last modified
CVE-2026-90284 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: firmware_loader: do not queue completed sysfs fallback requests fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to pending_fw_head. device_add() publishes the fallback loading interface, so a userspace helper which discovers the device by scanning sysfs can write 0 to the loading attribute and complete the request before it is queued as pending. In that interleaving firmware_loading_store() calls fw_state_done() while pending_list still points to itself, so it cannot remove an entry from pending_fw_head.
Description
In the Linux kernel, the following vulnerability has been resolved: firmware_loader: do not queue completed sysfs fallback requests fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to pending_fw_head. device_add() publishes the fallback loading interface, so a userspace helper which discovers the device by scanning sysfs can write 0 to the loading attribute and complete the request before it is queued as pending. In that interleaving firmware_loading_store() calls fw_state_done() while pending_list still points to itself, so it cannot remove an entry from pending_fw_head. The subsequent unconditional list_add() then queues an already-completed fw_priv. Once the request is released, pending_fw_head can retain a pointer to freed memory and the next fallback request can fault while validating the list. Only in-flight fallback requests need suspend or reboot abort handling. If the request is already DONE after device_add(), return success from the fallback path without sending another uevent, waiting again, or queueing it as pending. This preserves the invariant that pending_fw_head contains only active fallback requests.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= ecb739cf15a9bae040ce6b60209b78b92512d120, < c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7; >= 75d95e2e39b27f733f21e6668af1c9893a97de5e, < 93a2385730540105df8524447dcc11309ad280f9; >= 75d95e2e39b27f733f21e6668af1c9893a97de5e, < ea33fac0df7fe7b49a4b27acb83e227b82317d1d; >= 75d95e2e39b27f733f21e6668af1c9893a97de5e, < 5a250bff75a446374c05622973b18b4ab662b504; >= 75d95e2e39b27f733f21e6668af1c9893a97de5e, < 85aeb8fc61839098ae0942ccba86e669c08e75d4; >= 75d95e2e39b27f733f21e6668af1c9893a97de5e, < 6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b; >= 75d95e2e39b27f733f21e6668af1c9893a97de5e, < fb4824880b0dba0e7b3a497c46c642f979630392; >= 75d95e2e39b27f733f21e6668af1c9893a97de5e, < b48373c901951fad1a26bd7c33ad91172b3945b5; 67cf0fbcac0d42d4d4686cddc1e39f465bbfec37; d09639528b66b5c7c20dc8f7fb8928aacabd40bb; c14a54675db7131791402fa22fb0fa6da1f5fb66; >= 5.10.58, < 5.10.270; >= 4.19.203, < 4.20; >= 5.4.140, < 5.5; >= 5.13.10, < 5.14 |
| Linux | Linux | 5.14 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90284?
How severe is CVE-2026-90284?
How do I fix CVE-2026-90284?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90279In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9028The CorvusPay WooCommerce Payment Gateway plugin for WordPre…5.3
- CVE-2026-90280In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90281In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90282In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90283In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90285In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90286In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-90287In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90288In the Linux kernel, the following vulnerability has been re…7.4
- CVE-2026-90289In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-9029A user with Editor permissions can place a malicious script …5.4
Are you affected by CVE-2026-90284?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
