---
id: CVE-2026-90140
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  cuse: wait for pending RCU callbacks on module exit

  Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"),
  fuse_conn_put() frees the fuse_conn through call_rcu(…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  cuse: wait for pending RCU callbacks on module exit

  Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"),
  fuse_conn_put() frees the fuse_conn through call_rcu(…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= bfbab62ca69f72bcd14ea30de1fb98f6080ad464 <
    7fe415e1cd8fa875be263670c0ab47109818abb6
  - >-
    Linux >= a8f650b93e55764ca9ff8e1ddebc151f57024086 <
    45ae914b2f6ea56fc2f1c017fdee4e995bcb4c0e
  - >-
    Linux >= 535e9bd0e8f8d8cfdc29de7cdb902b5041427fe6 <
    ac5c499413385cea3e0220d6050408d50842891d
  - >-
    Linux >= 053fc4f755ad43cf35210677bcba798ccdc48d0c <
    a1b46aee33d83f14ed62d7fdef1a91d3e0b732a9
  - >-
    Linux >= 053fc4f755ad43cf35210677bcba798ccdc48d0c <
    389bd349ddbcf90dbd8a4f2a4ab6e552d53df134
  - >-
    Linux >= 053fc4f755ad43cf35210677bcba798ccdc48d0c <
    c40f3f24839f8404325a2099e26c2a04786ae309
  - >-
    Linux >= 053fc4f755ad43cf35210677bcba798ccdc48d0c <
    4deb3edead0c0e172cc7349e8855d741d3c5e162
  - Linux >= 5.15.166 < 5.15.221
  - Linux >= 6.1.107 < 6.1.188
  - Linux >= 6.6.48 < 6.6.157
  - Linux 6.8
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:06.710'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90140'
references:
  - url: 'https://git.kernel.org/stable/c/389bd349ddbcf90dbd8a4f2a4ab6e552d53df134'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/45ae914b2f6ea56fc2f1c017fdee4e995bcb4c0e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4deb3edead0c0e172cc7349e8855d741d3c5e162'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7fe415e1cd8fa875be263670c0ab47109818abb6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a1b46aee33d83f14ed62d7fdef1a91d3e0b732a9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ac5c499413385cea3e0220d6050408d50842891d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c40f3f24839f8404325a2099e26c2a04786ae309'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.878Z'
epss: 0.00205
epssPercentile: 0.09379
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

cuse: wait for pending RCU callbacks on module exit

Since commit 053fc4f755ad ("fuse: fix UAF in rcu pathwalks"),
fuse_conn_put() frees the fuse_conn through call_rcu() rather than
synchronously.  For cuse, fc->release is cuse_fc_release(), which
lives in the cuse module.  If the module is removed before the RCU
grace period ends, the callback jumps into freed module memory:

      userspace / module unload      |        RCU softirq
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 close(/dev/cuse)                    |
  cuse_channel_release()             |
   fuse_dev_release()                |
    fuse_conn_put(fch->conn)         |
     call_rcu(delayed_release) ------+---> callback queued
                                     |
 rmmod cuse                          |
  cuse_exit()                        |
   cuse_channel_destroy()            |
   ...                               |
   return                            |
                                     |
 <module text freed>                 |
                                     |  rcu_do_batch()
                                     |   delayed_release()
                                     |    fc->release()
                                     |     -> cuse_fc_release()
                                     |        ^^^ freed text!

The freed module text is unmapped by vfree(), so the jump into the
stale callback triggers a page-fault Oops.  If the virtual address
is subsequently reused, the callback could execute unrelated code
(undefined behaviour).

Fix this by calling rcu_barrier() in cuse_exit() so that any pending
fuse_conn release callback completes before the module is removed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
