← Back to CVE List
CVE-2026-90140NVD
Vulnerability Summary
In the Linux kernel, the following vulnerability has been resolved:
cuse: wait for pending RCU callbacks on module exit
Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"),
fuse_conn_put() frees the fuse_conn through call_rcu() rather than
synchronously. For cuse, fc->release is cuse_fc_release(), which
lives in the cuse module. If the module is removed before the RCU
grace period ends, the callback jumps into freed module memory:
userspace / module unload | RCU softirq
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
close(/dev/cuse) |
cuse_channel_release() |
fuse_dev_release() |
fuse_conn_put(fch->conn) |
call_rcu(delayed_release) ------+---> callback queued
|
rmmod cuse |
cuse_exit() |
cuse_channel_destroy() |
... |
return |
|
<module text freed> |
| rcu_do_batch()
| delayed_release()
| fc->release()
| -> cuse_fc_release()
| ^^^ freed text!
The freed module text is unmapped by vfree(), so the jump into the
stale callback triggers a page-fault Oops. If the virtual address
is subsequently reused, the callback could execute unrelated code
(undefined behaviour).
Fix this by calling rcu_barrier() in cuse_exit() so that any pending
fuse_conn release callback completes before the module is removed.
cuse: wait for pending RCU callbacks on module exit
Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"),
fuse_conn_put() frees the fuse_conn through call_rcu() rather than
synchronously. For cuse, fc->release is cuse_fc_release(), which
lives in the cuse module. If the module is removed before the RCU
grace period ends, the callback jumps into freed module memory:
userspace / module unload | RCU softirq
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
close(/dev/cuse) |
cuse_channel_release() |
fuse_dev_release() |
fuse_conn_put(fch->conn) |
call_rcu(delayed_release) ------+---> callback queued
|
rmmod cuse |
cuse_exit() |
cuse_channel_destroy() |
... |
return |
|
<module text freed> |
| rcu_do_batch()
| delayed_release()
| fc->release()
| -> cuse_fc_release()
| ^^^ freed text!
The freed module text is unmapped by vfree(), so the jump into the
stale callback triggers a page-fault Oops. If the virtual address
is subsequently reused, the callback could execute unrelated code
(undefined behaviour).
Fix this by calling rcu_barrier() in cuse_exit() so that any pending
fuse_conn release callback completes before the module is removed.
Affected & Patched Versions
- Linux Linux >= bfbab62ca69f72bcd14ea30de1fb98f6080ad464 and < 7fe415e1cd8fa875be263670c0ab47109818abb6
- Linux Linux >= a8f650b93e55764ca9ff8e1ddebc151f57024086 and < 45ae914b2f6ea56fc2f1c017fdee4e995bcb4c0e
- Linux Linux >= 535e9bd0e8f8d8cfdc29de7cdb902b5041427fe6 and < ac5c499413385cea3e0220d6050408d50842891d
- Linux Linux >= 053fc4f755ad43cf35210677bcba798ccdc48d0c and < a1b46aee33d83f14ed62d7fdef1a91d3e0b732a9
- Linux Linux >= 053fc4f755ad43cf35210677bcba798ccdc48d0c and < 389bd349ddbcf90dbd8a4f2a4ab6e552d53df134
- Linux Linux >= 053fc4f755ad43cf35210677bcba798ccdc48d0c and < c40f3f24839f8404325a2099e26c2a04786ae309
- Linux Linux >= 053fc4f755ad43cf35210677bcba798ccdc48d0c and < 4deb3edead0c0e172cc7349e8855d741d3c5e162
- Linux Linux >= 5.15.166 and < 5.15.221
- Linux Linux >= 6.1.107 and < 6.1.188
- Linux Linux >= 6.6.48 and < 6.6.157
- Linux Linux >= 6.8
- Linux Linux 7fe415e1cd8fa875be263670c0ab47109818abb6
- Linux Linux 45ae914b2f6ea56fc2f1c017fdee4e995bcb4c0e
- Linux Linux ac5c499413385cea3e0220d6050408d50842891d
- Linux Linux a1b46aee33d83f14ed62d7fdef1a91d3e0b732a9
- Linux Linux 389bd349ddbcf90dbd8a4f2a4ab6e552d53df134
- Linux Linux c40f3f24839f8404325a2099e26c2a04786ae309
- Linux Linux 4deb3edead0c0e172cc7349e8855d741d3c5e162
- Linux Linux 5.15.221
- Linux Linux 6.1.188
- Linux Linux 6.6.157
External References
- https://git.kernel.org/stable/c/7fe415e1cd8fa875be263670c0ab47109818abb6
- https://git.kernel.org/stable/c/45ae914b2f6ea56fc2f1c017fdee4e995bcb4c0e
- https://git.kernel.org/stable/c/ac5c499413385cea3e0220d6050408d50842891d
- https://git.kernel.org/stable/c/a1b46aee33d83f14ed62d7fdef1a91d3e0b732a9
- https://git.kernel.org/stable/c/389bd349ddbcf90dbd8a4f2a4ab6e552d53df134
- https://git.kernel.org/stable/c/c40f3f24839f8404325a2099e26c2a04786ae309
- https://git.kernel.org/stable/c/4deb3edead0c0e172cc7349e8855d741d3c5e162