Junglewise Threat Intelligence

CVE-2026-90303: Linux kernel ARM use-after-free in show_pte()

CVE-2026-90303 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ARM architecture memory fault handler may crash or behave unpredictably when debug output is enabled. A race condition allows one thread to free memory pages while another thread is still reading them, causing a kernel panic or system instability. This affects ARM systems running with debugging features enabled.

Technical details

A use-after-free vulnerability exists in the ARM fault handler's show_pte() function, triggered when CONFIG_DEBUG_USER=y and the cmdline parameter "user_debug=31" is set. The vulnerability occurs because show_pte() traverses page table structures without holding the memory mapping lock (mmap_write_lock). If a concurrent munmap() call frees page table pages while show_pte() is still reading them, a use-after-free condition results. Under CONFIG_ARM_LPAE, this can cause kernel panic. The fix acquires mmap_write_lock() around show_pte() for user-space faults (addr < TASK_SIZE) to serialize access and prevent concurrent modification. Kernel faults are left unchanged to avoid deadlock risk in the oops path. A patch is available in Linux kernel commit 1039bffd6ae9c75b42b7d148d6c1106134107b66.

Affected products

  • Linux Linux Kernel All versions (patch available from 2026-08-05)

Timeline

  • 2026-09-17: disclosed: CVE-2026-90303 published
  • 2026-08-05: patched: Upstream patch merged to ARM architecture branch

References

Related threats