CVE-2026-90044: usb: gadget: f_fs: Fix Use-After-Free in AIO error path

Published Sep 16, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: ffs: Fix Use-After-Free in AIO error path

In ffsepfilewriteiter() and ffsepfilereaditer(), when ffsepfileio() fails with an error other than -EIOCBQUEUED, the iodata structure (p) is freed. However, for AIO operations, the kiocb cancel function was already armed and kiocb->private was set to p.

If a concurrent cancel operation (such as sysiocancel()) executes after ffsepfileio() fails but before the function frees p, a Use-After-Free can occur when the cancellation handler accesses the freed pointer.

To securely fix this race condition, we must properly un-arm the cancellation. Invoking kiocb->kicomplete() does exactly this by acquiring ctx->ctxlock and safely removing the kiocb from the active sequence. In doing so, it ensures that a parallel iocancel can no longer discover the kiocb, effectively closing the race window.

We then return -EIOCBQUEUED to notify the VFS layer that the kiocb has been consumed and it should avoid attempting to complete the request again or triggering subsequent completion handlers.

Event History

Sep 16, 2026
CVE Published
via MITRE·10:33 AM
Data Sourced
via MITRE·10:33 AM
Description

Frequently Asked Questions

1

What conditions are required to trigger the race?

The affected code path requires an asynchronous I/O operation through the FunctionFS endpoint-file read or write handlers to fail with an error other than -EIOCBQUEUED. A concurrent cancellation operation, such as sys_io_cancel(), must then run in the window after cancellation has been armed but while the failed operation's io_data is being freed.

2

What component is affected?

The issue is in the Linux kernel USB gadget FunctionFS implementation, specifically the AIO error paths in ffs_epfile_write_iter() and ffs_epfile_read_iter().

3

How does the fix prevent use-after-free?

The fix invokes kiocb->ki_complete() before releasing the I/O data in the affected error path. This acquires the AIO context lock and removes the kiocb from the active sequence, preventing a parallel cancellation from finding and dereferencing the stale private pointer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203