Answer in brief
CVE-2026-90284 records a Unknown severity vulnerability in firmware_loader: do not queue completed sysfs fallback requests. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ecb739cf15a9bae040ce6b60209b78b92512d120 <c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7 || >=75d95e2e39b27f733f21e6668af1c9893a97de5e <93a2385730540105df8524447dcc11309ad280f9 || >=75d95e2e39b27f733f21e6668af1c9893a97de5e <ea33fac0df7fe7b49a4b27acb83e227b82317d1d || >=75d95e2e39b27f733f21e6668af1c9893a97de5e <5a250bff75a446374c05622973b18b4ab662b504 || >=75d95e2e39b27f733f21e6668af1c9893a97de5e <85aeb8fc61839098ae0942ccba86e669c08e75d4 || >=75d95e2e39b27f733f21e6668af1c9893a97de5e <6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b || >=75d95e2e39b27f733f21e6668af1c9893a97de5e <fb4824880b0dba0e7b3a497c46c642f979630392 || >=75d95e2e39b27f733f21e6668af1c9893a97de5e <b48373c901951fad1a26bd7c33ad91172b3945b5 || 67cf0fbcac0d42d4d4686cddc1e39f465bbfec37 || d09639528b66b5c7c20dc8f7fb8928aacabd40bb || c14a54675db7131791402fa22fb0fa6da1f5fb66 || >=5.10.58 <5.10.270 || >=4.19.203 <4.20 || >=5.4.140 <5.5 || >=5.13.10 <5.14 | c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7, 93a2385730540105df8524447dcc11309ad280f9, ea33fac0df7fe7b49a4b27acb83e227b82317d1d, 5a250bff75a446374c05622973b18b4ab662b504, 85aeb8fc61839098ae0942ccba86e669c08e75d4, 6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b, fb4824880b0dba0e7b3a497c46c642f979630392, b48373c901951fad1a26bd7c33ad91172b3945b5, 5.10.270, 4.20, 5.5, 5.14 |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: firmware_loader: do not queue completed sysfs fallback requests fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to pending_fw_head. device_add() publishes the fallback loading interface, so a userspace helper which discovers the device by scanning sysfs can write 0 to the loading attribute and complete the request before it is queued as pending. In that interleaving firmware_loading_store() calls fw_state_done() while pending_list still points to itself, so it cannot remove an entry from pending_fw_head. The subsequent unconditional list_add() then queues an already-completed fw_priv. Once the request is released, pending_fw_head can retain a pointer to freed memory and the next fallback request can fault while validating the list. Only in-flight fallback requests need suspend or reboot abort handling. If the request is already DONE after device_add(), return success from the fallback path without sending another uevent, waiting again, or queueing it as pending. This preserves the invariant that pending_fw_head contains only active fallback requests.
Quoted source text, attributed separately from HOL analysis.