PT-2026-94651 · Linux · Linux Kernel

CVE-2026-90303

·

Published

2026-09-17

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the show pte() function when CONFIG DEBUG USER=y and the user debug=31 command line option is enabled. This occurs because a user fault can trigger show pte() without a lock; if another thread in the same process concurrently calls munmap(), page table pages may be freed while show pte() is still traversing them. In environments where CONFIG ARM LPAE=y is enabled, this can lead to a kernel panic if PMD page tables are freed during the execution of show pte(). To resolve this, the mmap write lock() must be acquired around show pte() for user faults, and the function must be restricted to user-space addresses where addr is less than TASK SIZE to prevent security implications and ensure the lock of tsk->mm properly protects the virtual memory.
Recommendations As a temporary mitigation, avoid setting the user debug=31 command line option or disable CONFIG DEBUG USER until the system is updated to a version where mmap write lock() is acquired around the show pte() function.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101873
CVE-2026-90303
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel