๐Ÿ” CVE Alert

CVE-2026-90323

UNKNOWN 0.0

ublk: validate auto buf reg before taking uring_cmd

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ublk: validate auto buf reg before taking uring_cmd With UBLK_F_AUTO_BUF_REG, invalid sqe->addr can fail after ublk_fill_io_cmd() has set UBLK_IO_FLAG_ACTIVE. The uring_cmd is completed while the tag stays active, which can hang teardown. Split validation from buffer apply so the check has no side effects, then take the uring_cmd and store the already-validated buffer. Apply the same order in FETCH so io->buf is not written before __ublk_fetch() state checks.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
52460dda3a775a73f226312b43c0a0211e8665ea < 653d22269a8b83b491f7f186a5d7872f14e6ddca 52460dda3a775a73f226312b43c0a0211e8665ea < ca5a01eee34c7cbe0f531a613b0292a3ad1a419b
Linux / Linux
6.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/653d22269a8b83b491f7f186a5d7872f14e6ddca git.kernel.org: https://git.kernel.org/stable/c/ca5a01eee34c7cbe0f531a613b0292a3ad1a419b