{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90045","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.783Z","datePublished":"2026-09-16T10:33:42.411Z","dateUpdated":"2026-09-21T13:15:19.588Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-21T13:15:19.588Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: gadget: ffs: fix mm lifetime handling\n\nio_data stores a pointer to the submitting task's mm_struct,\nbut does not currently hold a reference to it while async\nrequests are pending.\n\nThis can result in a use-after-free if the task exits before\ncompletion handling finishes.\n\nTake a reference with mmgrab() when queuing the read request\nand release it with mmdrop() on request completion."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached via local aio_read/io_submit on FunctionFS ep files (ffs_epfile_read_iter → ffs_epfile_io), not by parsing USB host packets. This is the gadget userspace API; prior f_fs AIO UAFs (CVE-2024-36894, CVE-2025-71074) are scored Local, which is also the higher-severity vector versus Physical.\nAC:L - The attacker submits the AIO read, can complete it locally (dummy_hcd or an already-bound gadget) and exit while the ordered io_completion_wq worker is still pending. Both sides of the mm-lifetime race are attacker-driven and freely retryable, so this is not AC:H.\nPR:L - ffs_epfile_open has no capability check. FunctionFS mounts commonly set uid=/gid=/fmode= so unprivileged gadget daemons (adbd/shell, MTP) can open ep files; mounting needs init-namespace CAP_SYS_ADMIN, but using already-mounted endpoints does not.\nUI:N - The attacker performs io_submit and process exit itself. No separate victim action is required beyond an already-deployed FunctionFS gadget.\nS:U - The mm_struct use-after-free corrupts host kernel state within the same security authority. This is standard local kernel privilege escalation, not a VM, IOMMU, or sandbox escape.\nC:H - Use-after-free of mm_struct lets kthread_use_mm/switch_mm consume a reclaimed mm (including mm->pgd) and copy_to_iter through attacker-influenced page tables, yielding an arbitrary read primitive. Per scoring guidance, UAF is Confidentiality High.\nI:H - kthread_use_mm on a sprayed mm_struct can install attacker-controlled page tables, and ffs_copy_to_iter then writes the USB payload through them, giving an arbitrary write and control-flow hijack primitive. Per scoring guidance, UAF is Integrity High.\nA:H - Using a freed mm_struct in kthread_use_mm/switch_mm and copy_to_iter reliably oopses or panics the kernel even without a full exploit, so availability impact is High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/usb/gadget/function/f_fs.c"],"versions":[{"version":"2e4c7553cd6f9c68bb741582dcb614edcbeca70f","lessThan":"1625827648f4e1595ea6ba5521bc87ee5088b32b","status":"affected","versionType":"git"},{"version":"2e4c7553cd6f9c68bb741582dcb614edcbeca70f","lessThan":"f3d31484b3f26d63c09e5569ebfaa1079a17f171","status":"affected","versionType":"git"},{"version":"2e4c7553cd6f9c68bb741582dcb614edcbeca70f","lessThan":"7411de0ce3b45286de1de82526795658ea6eacb0","status":"affected","versionType":"git"},{"version":"2e4c7553cd6f9c68bb741582dcb614edcbeca70f","lessThan":"5eb5c72c72fef76cb765ef1669b62b6a3ba1bfc8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/usb/gadget/function/f_fs.c"],"versions":[{"version":"3.15","status":"affected"},{"version":"0","lessThan":"3.15","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1625827648f4e1595ea6ba5521bc87ee5088b32b"},{"url":"https://git.kernel.org/stable/c/f3d31484b3f26d63c09e5569ebfaa1079a17f171"},{"url":"https://git.kernel.org/stable/c/7411de0ce3b45286de1de82526795658ea6eacb0"},{"url":"https://git.kernel.org/stable/c/5eb5c72c72fef76cb765ef1669b62b6a3ba1bfc8"}],"title":"USB: gadget: ffs: fix mm lifetime handling","x_generator":{"engine":"bippy-1.2.0"}}}}