Junglewise Threat Intelligence

CVE-2026-90319: Linux kernel RapidIO use-after-free in mport unregister

CVE-2026-90319 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RapidIO driver contains a use-after-free vulnerability in device initialization error handling. When RapidIO network device registration fails, a dangling pointer is left pointing to freed memory. A later unregister operation can dereference this freed pointer, potentially causing system crashes or allowing privilege escalation on systems using RapidIO hardware interconnects.

Technical details

A use-after-free vulnerability exists in the RapidIO driver's rio_scan_alloc_net() function. When rio_add_net() fails, the function correctly releases the device via put_device(), which triggers the device release callback and frees the rio_net structure. However, the mport->net pointer is left dangling, pointing to the freed rio_net object. A subsequent mport unregister path can dereference this dangling pointer and attempt to free the same rio_net again, causing a double-free or use-after-free. The fix clears mport->net to NULL in the rio_add_net() failure path. This affects the RapidIO interconnect fabric driver in the Linux kernel; attack vector requires kernel module/driver functionality for RapidIO capable systems.

Affected products

  • Linux Linux Kernel multiple (patches applied across stable series 3.x through 7.x)

Timeline

  • 2026-09-17: disclosed
  • 2026-07-08: patched: Upstream fix committed; backported to stable branches

References

Related threats