๐Ÿ” CVE Alert

CVE-2026-90044

UNKNOWN 0.0

usb: gadget: f_fs: Fix Use-After-Free in AIO error path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error path In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io() fails with an error other than -EIOCBQUEUED, the io_data structure (`p`) is freed. However, for AIO operations, the kiocb cancel function was already armed and kiocb->private was set to `p`. If a concurrent cancel operation (such as sys_io_cancel()) executes after ffs_epfile_io() fails but before the function frees `p`, a Use-After-Free can occur when the cancellation handler accesses the freed pointer. To securely fix this race condition, we must properly un-arm the cancellation. Invoking `kiocb->ki_complete()` does exactly this by acquiring `ctx->ctx_lock` and safely removing the kiocb from the active sequence. In doing so, it ensures that a parallel io_cancel can no longer discover the kiocb, effectively closing the race window. We then return -EIOCBQUEUED to notify the VFS layer that the kiocb has been consumed and it should avoid attempting to complete the request again or triggering subsequent completion handlers.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
de2080d41b5d584205e408d72021f0f335a046fc < 153b5ecd29ed055562400bc17c91df3fd869b0ce de2080d41b5d584205e408d72021f0f335a046fc < 4a2fb2d12b87b43724230abb52a1440617c7b6cc de2080d41b5d584205e408d72021f0f335a046fc < e78dcb1f7ec271449c54984dc90c62a5ba272de7
Linux / Linux
4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/153b5ecd29ed055562400bc17c91df3fd869b0ce git.kernel.org: https://git.kernel.org/stable/c/4a2fb2d12b87b43724230abb52a1440617c7b6cc git.kernel.org: https://git.kernel.org/stable/c/e78dcb1f7ec271449c54984dc90c62a5ba272de7