CVE-2026-90303

Source
https://cve.org/CVERecord?id=CVE-2026-90303
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90303.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90303
Downstream
Published
2026-09-17T16:08:26Z
Modified
2026-09-19T03:47:28Z
Summary
ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults
Details

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults

When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set, a user fault may trigger show_pte() without any lock. If another thread in the same process concurrently calls munmap(), the page table pages may be freed while show_pte() is still traversing them, causing a use-after-free in show_pte().

If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table of PMD are freed when show_pte() is running.

Acquire mmap_write_lock() around show_pte() for user faults to fix the contention.

For user faults, additionally restrict that show_pte() is called only when the addr is a user-space address (addr < TASK_SIZE). This is because the lock of tsk->mm only protects the virtual memory of user address space, furthermore, dumping the page tables of a kernel-space address for user faults is unnecessary and may have security implications.

Keep everything unchanged for kernel faults, because the kernel is already in the "oops" state, acquiring a lock may risk a deadlock.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90303.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6d021b724481fbb908eb29384898deb9f00dfe70
Fixed
ab14f07952adfe735d86a53518f8cd576dfd5892
Fixed
07e4d5380f2a844ab7a1b440dde350caf561cbb0
Fixed
2a14d7797a49a47bccd1a9327fd69da838dcb0dd
Fixed
63e3c958a602d0896a101a897c2361878c266ca7
Fixed
59bbf86d0ff9373bfa033ca123c1e924f09f1eba
Fixed
c71f9a56520b419e55d173052629f2324deb5549
Fixed
720408d98d9fb3c91a12090436734c8c61f04545
Fixed
1039bffd6ae9c75b42b7d148d6c1106134107b66

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90303.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90303.json"