Race condition in Linux kernel - CVE-2026-90284
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the firmware sysfs fallback loader when a userspace helper completes a firmware request after the loading interface is exposed but before the request is added to the pending request list. A local user can write 0 to the loading attribute to cause a denial of service.
Affected software
How to mitigate CVE-2026-90284
External References
- https://git.kernel.org/stable/c/5a250bff75a446374c05622973b18b4ab662b504
- https://git.kernel.org/stable/c/6eaa632d0ed7bbb84f9cb670e5ec4e2cecf4cc7b
- https://git.kernel.org/stable/c/85aeb8fc61839098ae0942ccba86e669c08e75d4
- https://git.kernel.org/stable/c/93a2385730540105df8524447dcc11309ad280f9
- https://git.kernel.org/stable/c/b48373c901951fad1a26bd7c33ad91172b3945b5
- https://git.kernel.org/stable/c/c8b97c5130f27b64fa2cfe1aa4bebb13f724c6c7
- https://git.kernel.org/stable/c/ea33fac0df7fe7b49a4b27acb83e227b82317d1d
- https://git.kernel.org/stable/c/fb4824880b0dba0e7b3a497c46c642f979630392