๐Ÿ” CVE Alert

CVE-2026-90010

UNKNOWN 0.0

scsi: bsg: Cap io_uring sense copy to max_response_len

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Cap io_uring sense copy to max_response_len Completion copied scmd->sense_len to the user response buffer without honoring max_response_len. After a valid sense, the midlayer sets sense_len to the real length (up to SCSI_SENSE_BUFFERSIZE), so a smaller user buffer was overrun.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7b6d3255e7f8c6df2d21504c47808e3ce84649ac < 5d326efc334ea21afd8161f6ca53e17de71948a9 7b6d3255e7f8c6df2d21504c47808e3ce84649ac < ece06de726737e887dc0225c8283477624f8ae21
Linux / Linux
7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5d326efc334ea21afd8161f6ca53e17de71948a9 git.kernel.org: https://git.kernel.org/stable/c/ece06de726737e887dc0225c8283477624f8ae21