๐Ÿ” CVE Alert

CVE-2026-90267

UNKNOWN 0.0

scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails sd_set_special_bvec() allocates a special payload page for UNMAP and WRITE SAME commands. If scsi_alloc_sgtables() fails afterward in sd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI midlayer does not call uninit_command() because RQF_DONTPREP is not set yet, leaking the page. Call sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after freeing the page.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
81d926e8b5520e38f1f72dd7bb7cfc81c1a69d87 < 5d7d1b8b525e5eff33a01d07dfcf7bdd3b6d790d 81d926e8b5520e38f1f72dd7bb7cfc81c1a69d87 < bb31844d88b77138b67aa20c3600203baff40140
Linux / Linux
4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5d7d1b8b525e5eff33a01d07dfcf7bdd3b6d790d git.kernel.org: https://git.kernel.org/stable/c/bb31844d88b77138b67aa20c3600203baff40140