CVE-2026-90227
nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed()
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() Unlike IO_CMD / IO64_CMD, NVME_IOCTL_SUBMIT_IO never calls nvme_cmd_allowed(). Unprivileged callers can thus issue I/O on a partition device or write through a read-only file descriptor. Pass flags and open_for_write through and reject disallowed commands with -EACCES.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new unknown vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c35cd98eed1a863e8dd51073953563cd8c907f68 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 95b0591d51dbf9e618d7845883d535e88ad7c8af 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 736b7c6adc7a65c4411beff197b6a634f7a6ca27 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b116e9dae433ff631f94c36c61a7a78fe400ed1e 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b53d495c7f0db46b6748b5ade48371a10dd5d3bc 0 < 6.6.157 0 < 6.12.110 0 < 6.18.52 0 < 7.2.6
Linux / Linux
All versions affected References
git.kernel.org: https://git.kernel.org/stable/c/c35cd98eed1a863e8dd51073953563cd8c907f68 git.kernel.org: https://git.kernel.org/stable/c/95b0591d51dbf9e618d7845883d535e88ad7c8af git.kernel.org: https://git.kernel.org/stable/c/736b7c6adc7a65c4411beff197b6a634f7a6ca27 git.kernel.org: https://git.kernel.org/stable/c/b116e9dae433ff631f94c36c61a7a78fe400ed1e git.kernel.org: https://git.kernel.org/stable/c/b53d495c7f0db46b6748b5ade48371a10dd5d3bc