Answer in brief
CVE-2026-90303 records a Unknown severity vulnerability in ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6d021b724481fbb908eb29384898deb9f00dfe70 <ab14f07952adfe735d86a53518f8cd576dfd5892 || >=6d021b724481fbb908eb29384898deb9f00dfe70 <07e4d5380f2a844ab7a1b440dde350caf561cbb0 || >=6d021b724481fbb908eb29384898deb9f00dfe70 <2a14d7797a49a47bccd1a9327fd69da838dcb0dd || >=6d021b724481fbb908eb29384898deb9f00dfe70 <63e3c958a602d0896a101a897c2361878c266ca7 || >=6d021b724481fbb908eb29384898deb9f00dfe70 <59bbf86d0ff9373bfa033ca123c1e924f09f1eba || >=6d021b724481fbb908eb29384898deb9f00dfe70 <c71f9a56520b419e55d173052629f2324deb5549 || >=6d021b724481fbb908eb29384898deb9f00dfe70 <720408d98d9fb3c91a12090436734c8c61f04545 || >=6d021b724481fbb908eb29384898deb9f00dfe70 <1039bffd6ae9c75b42b7d148d6c1106134107b66 | ab14f07952adfe735d86a53518f8cd576dfd5892, 07e4d5380f2a844ab7a1b440dde350caf561cbb0, 2a14d7797a49a47bccd1a9327fd69da838dcb0dd, 63e3c958a602d0896a101a897c2361878c266ca7, 59bbf86d0ff9373bfa033ca123c1e924f09f1eba, c71f9a56520b419e55d173052629f2324deb5549, 720408d98d9fb3c91a12090436734c8c61f04545, 1039bffd6ae9c75b42b7d148d6c1106134107b66 |
| Linux/Linuxgeneric | 4.0 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set, a user fault may trigger show_pte() without any lock. If another thread in the same process concurrently calls munmap(), the page table pages may be freed while show_pte() is still traversing them, causing a use-after-free in show_pte(). If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table of PMD are freed when show_pte() is running. Acquire mmap_write_lock() around show_pte() for user faults to fix the contention. For user faults, additionally restrict that show_pte() is called only when the addr is a user-space address (addr < TASK_SIZE). This is because the lock of tsk->mm only protects the virtual memory of user address space, furthermore, dumping the page tables of a kernel-space address for user faults is unnecessary and may have security implications. Keep everything unchanged for kernel faults, because the kernel is already in the "oops" state, acquiring a lock may risk a deadlock.
Quoted source text, attributed separately from HOL analysis.