{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89764","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.764Z","datePublished":"2026-09-11T19:47:05.092Z","dateUpdated":"2026-09-13T06:34:08.821Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:34:08.821Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrust: devres: fix race between concurrent revokers\n\nThere is a potential race condition when two paths try to revoke a\nDevres concurrently.\n\nThe driver core's devres_release_all() calls Revocable::revoke() via the\nrelease callback, while Devres::drop() calls revoke_nosync() on another\nCPU.\n\nThe revoker that does not claim the is_available swap returns\nimmediately, but the revoker that did may still be executing\ndrop_in_place() on the inner data. This can cause a use-after-free when\nthe other revoker's caller proceeds to drop adjacent resources that\ndrop_in_place() still references (e.g., Devres<DmaMappedSgt> racing with\nSGTable freeing the backing sg_table and pages).\n\nFix this by adding a Completion. The release callback signals the\nCompletion after revoke() finishes, and Devres::drop() waits for it when\nit loses the is_available swap. This ensures the wrapped object is fully\ntorn down before Devres::drop() returns."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The race is in the Rust Devres teardown path (Devres::drop vs devres_release_all release callback), reached by local driver unbind/rmmod/sysfs unbind or hot-unplug of Rust-using devices (nova-core NVIDIA GPU, TH1520 PWM, PCI/platform samples). It is not reachable from network packets or a remote protocol.\nAC:L - The attacker can drive both sides: one CPU in device_unbind_cleanup()/devres_release_all() calling Revocable::revoke() (which sleeps in synchronize_rcu(), widening the window), and another dropping the Devres-containing object (SGTable, Arc<irq::Registration>, PWM Chip data). That is an attacker-controlled race, not an uncontrolled layout condition.\nPR:L - Unbind/rmmod is privileged, but per driver-removal UAF scoring an unprivileged local user with the device (DRM render node, PWM sysfs on TH1520 boards, IRQ-generating I/O) can hold/drop Devres-backed objects or keep the other CPU in teardown while the device is unbound. This does not require init-namespace root or a user-namespace capability.\nUI:N - Exploitation does not need a separate victim action such as opening a file or clicking UI. The attacker performs device I/O or holds extra refs themselves while routine unbind, module unload, or hot-unplug runs.\nS:U - Impact is kernel memory corruption and privilege escalation on the same host. It does not cross a VM, IOMMU, or other distinct security-authority boundary.\nC:H - The bug is a use-after-free: the losing revoker returns while drop_in_place() still uses inner data (e.g. dma_unmap_sgtable on SGTable pages, free_irq cookie, IoMem). UAF of those objects yields an arbitrary kernel read primitive.\nI:H - The same UAF of sg_table/pages, IRQ Registration handler state, or MMIO mappings is heap corruption exploitable for writes and control-flow hijack, not a bounded or integrity-neutral fault.\nA:H - Use-after-free of DMA mappings, IRQ registrations, or iomem during unbind can oops/panic the kernel even if not fully exploited, so availability impact is complete."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["rust/kernel/devres.rs"],"versions":[{"version":"05aa6fb1c21d7fb9df735da24096d793223789d5","lessThan":"c7e3d57c705ab1053a6a1bbef96795e792da1540","status":"affected","versionType":"git"},{"version":"05aa6fb1c21d7fb9df735da24096d793223789d5","lessThan":"acc516dfa1972d31836b50abc0115216cd0fccc5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["rust/kernel/devres.rs"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c7e3d57c705ab1053a6a1bbef96795e792da1540"},{"url":"https://git.kernel.org/stable/c/acc516dfa1972d31836b50abc0115216cd0fccc5"}],"title":"rust: devres: fix race between concurrent revokers","x_generator":{"engine":"bippy-1.2.0"}}}}