๐Ÿ” CVE Alert

CVE-2026-90227

UNKNOWN 0.0

nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() Unlike IO_CMD / IO64_CMD, NVME_IOCTL_SUBMIT_IO never calls nvme_cmd_allowed(). Unprivileged callers can thus issue I/O on a partition device or write through a read-only file descriptor. Pass flags and open_for_write through and reject disallowed commands with -EACCES.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c35cd98eed1a863e8dd51073953563cd8c907f68 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 95b0591d51dbf9e618d7845883d535e88ad7c8af 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 736b7c6adc7a65c4411beff197b6a634f7a6ca27 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b116e9dae433ff631f94c36c61a7a78fe400ed1e 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b53d495c7f0db46b6748b5ade48371a10dd5d3bc 0 < 6.6.157 0 < 6.12.110 0 < 6.18.52 0 < 7.2.6
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c35cd98eed1a863e8dd51073953563cd8c907f68 git.kernel.org: https://git.kernel.org/stable/c/95b0591d51dbf9e618d7845883d535e88ad7c8af git.kernel.org: https://git.kernel.org/stable/c/736b7c6adc7a65c4411beff197b6a634f7a6ca27 git.kernel.org: https://git.kernel.org/stable/c/b116e9dae433ff631f94c36c61a7a78fe400ed1e git.kernel.org: https://git.kernel.org/stable/c/b53d495c7f0db46b6748b5ade48371a10dd5d3bc