CVE-2026-90044
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_fs: Fix Use-After-Free in AIO error path
In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io()
fails with an error other than -EIOCBQUEUED, the io_data structure (p) is
freed. However, for AIO operations, the kiocb cancel function was already
armed and kiocb->private was set to p.
If a concurrent cancel operation (such as sys_io_cancel()) executes after
ffs_epfile_io() fails but before the function frees p, a Use-After-Free
can occur when the cancellation handler accesses the freed pointer.
To securely fix this race condition, we must properly un-arm the
cancellation. Invoking kiocb->ki_complete() does exactly this by
acquiring ctx->ctx_lock and safely removing the kiocb from the active
sequence. In doing so, it ensures that a parallel io_cancel can no longer
discover the kiocb, effectively closing the race window.
We then return -EIOCBQUEUED to notify the VFS layer that the kiocb has been consumed and it should avoid attempting to complete the request again or triggering subsequent completion handlers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | de2080d41b5d584205e408d72021f0f335a046fc < 153b5ecd29ed055562400bc17c91df3fd869b0ce | affected |
| Linux | Linux | de2080d41b5d584205e408d72021f0f335a046fc < 4a2fb2d12b87b43724230abb52a1440617c7b6cc | affected |
| Linux | Linux | de2080d41b5d584205e408d72021f0f335a046fc < e78dcb1f7ec271449c54984dc90c62a5ba272de7 | affected |
| Linux | Linux | 4.0 | affected |
| Linux | Linux | 0 < 4.0 | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/153b5ecd29ed055562400bc17c91df3fd869b0ce
- https://git.kernel.org/stable/c/4a2fb2d12b87b43724230abb52a1440617c7b6cc
- https://git.kernel.org/stable/c/e78dcb1f7ec271449c54984dc90c62a5ba272de7
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.