-
CVE-2026-90267
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:08:02
- Zuletzt bearbeitet 17.09.2026 17:17:23
- Erkennungen
scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails
In the Linux kernel, the following vulnerability has been resolved:
scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails
sd_set_special_bvec() allocates a special payload page for UNMAP and
WRITE SAME commands. If scsi_alloc_sgtables() fails afterward in
sd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI
midlayer does not call uninit_command() because RQF_DONTPREP is not set
yet, leaking the page.
Call sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after
freeing the page.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
81d926e8b5520e38f1f72dd7bb7cfc81c1a69d87
Version <
5d7d1b8b525e5eff33a01d07dfcf7bdd3b6d790d
Status
affected
Version
81d926e8b5520e38f1f72dd7bb7cfc81c1a69d87
Version <
bb31844d88b77138b67aa20c3600203baff40140
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.12
Status
affected
Version
0
Version <
4.12
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.051 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/5d7d1b8b525e5eff33a01d07dfcf7bdd3b6d790d
https://git.kernel.org/stable/c/bb31844d88b77138b67aa20c3600203baff40140