CVE-2026-90284
Description
In the Linux kernel, the following vulnerability has been resolved: firmware_loader: do not queue completed sysfs fallback requests fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to pending_fw_head. device_add() publishes the fallback loading interface, so a userspace helper which discovers the device by scanning sysfs can write 0 to the loading attribute and complete the request before it is queued as pending. In that interleaving firmware_loading_store() calls fw_state_done() while pending_list still points to itself, so it cannot remove an entry from pending_fw_head. The subsequent unconditional list_add() then queues an already-completed fw_priv. Once the request is released, pending_fw_head can retain a pointer to freed memory and the next fallback request can fault while validating the list. Only in-flight fallback requests need suspend or reboot abort handling. If the request is already DONE after device_add(), return success from the fallback path without sending another uevent, waiting again, or queueing it as pending. This preserves the invariant that pending_fw_head contains only active fallback requests.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/5a250bff75a446374c05622973b18b4ab662b504
- https://git.kernel.org/stable/c/6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b
- https://git.kernel.org/stable/c/85aeb8fc61839098ae0942ccba86e669c08e75d4
- https://git.kernel.org/stable/c/93a2385730540105df8524447dcc11309ad280f9
- https://git.kernel.org/stable/c/b48373c901951fad1a26bd7c33ad91172b3945b5
- https://git.kernel.org/stable/c/c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7
- https://git.kernel.org/stable/c/ea33fac0df7fe7b49a4b27acb83e227b82317d1d
- https://git.kernel.org/stable/c/fb4824880b0dba0e7b3a497c46c642f979630392
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.