Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-90283— hugetlbfs: release subpool on fill_super failure

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: 在 Linux 内核中,以下漏洞已得到修复: hugetlbfs:在 fill_super 失败时释放 subpool 在指定了 或 挂载选项时,会分配一个 hugepage subpool(大页子池)。 还可能会为 保留大页。 如果在 subpool 创建成功后,根目录项(root dentry)创建失败,现有的错误处理路径使用 释放 subpool。这绕过了 ,可能导致与 相关的保留页记账未正确清除。 修复方法:在失败路径中改为调用 ,以与正常的 路径保持一致。

AI Predicted 5.5 Difficulty: Hard EPSS 0.23% · P13

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 7ca02d0ae586fe7df59632966a64f3f1a756ef05< f2d6cea221d777fab3ba18f805ba4c17c90e0b8b affected
7ca02d0ae586fe7df59632966a64f3f1a756ef05< 91c4f3a87862fd86594d5945512decbfa0b1d13d affected
7ca02d0ae586fe7df59632966a64f3f1a756ef05< 04f0354a4abf6793aa5b3f32e2b019ab206f344d affected
7ca02d0ae586fe7df59632966a64f3f1a756ef05< 5b7fc7a1ce2a5f2cd8ed80a883157c7108074e0b affected
7ca02d0ae586fe7df59632966a64f3f1a756ef05< 1d8be4ee81e73fcc52e58f47842d9a2277cfeaaa affected
7ca02d0ae586fe7df59632966a64f3f1a756ef05< dfe848cadfde4179a0691da34f4bed36ff7185b5 affected
7ca02d0ae586fe7df59632966a64f3f1a756ef05< dc2bd517ac0bce4ec7498644bd16b6db502df8e2 affected
7ca02d0ae586fe7df59632966a64f3f1a756ef05< 308ab73e97c87bd0e142b11758faab7f88d82854 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90283

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
hugetlbfs: release subpool on fill_super failure
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: hugetlbfs: release subpool on fill_super failure hugetlbfs_fill_super() allocates a hugepage subpool when size or min_size mount options are specified. hugepage_new_subpool() may also reserve huge pages for min_size. If root dentry creation fails after the subpool is created, the failure path frees the subpool with kfree(). This bypasses hugepage_put_subpool() and can leave min_size reservations charged. Use hugepage_put_subpool() on the failure path, matching the normal put_super path.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 7ca02d0ae586fe7df59632966a64f3f1a756ef05 ~ f2d6cea221d777fab3ba18f805ba4c17c90e0b8b -
Linux Linux 4.1 -

II. Public POCs for CVE-2026-90283

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90283

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-90283 (8)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90286 8.8 HIGH drm/amdgpu/gfx6: Use PFP on the compute queues too
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-90162 8.8 HIGH ksmbd: defer publishing granted locks to prevent UAF/double-free race
CVE-2026-90379 8.8 HIGH wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90371 8.8 HIGH wifi: mt76: fix RXDMAD_C buffer recycling race

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-90283

No comments yet


Leave a comment