« Volver al listado

CVE-2026-90323

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ublk: validate auto buf reg before taking uring_cmd

With UBLK_F_AUTO_BUF_REG, invalid sqe->addr can fail after ublk_fill_io_cmd() has set UBLK_IO_FLAG_ACTIVE. The uring_cmd is completed while the tag stays active, which can hang teardown.

Split validation from buffer apply so the check has no side effects, then take the uring_cmd and store the already-validated buffer. Apply the same order in FETCH so io->buf is not written before __ublk_fetch() state checks.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90323",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "52460dda3a775a73f226312b43c0a0211e8665ea",
              "lessThan": "653d22269a8b83b491f7f186a5d7872f14e6ddca",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "52460dda3a775a73f226312b43c0a0211e8665ea",
              "lessThan": "ca5a01eee34c7cbe0f531a613b0292a3ad1a419b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/block/ublk_drv.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/block/ublk_drv.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:30.307",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/653d22269a8b83b491f7f186a5d7872f14e6ddca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ca5a01eee34c7cbe0f531a613b0292a3ad1a419b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nublk: validate auto buf reg before taking uring_cmd\n\nWith UBLK_F_AUTO_BUF_REG, invalid sqe->addr can fail after\nublk_fill_io_cmd() has set UBLK_IO_FLAG_ACTIVE. The uring_cmd is\ncompleted while the tag stays active, which can hang teardown.\n\nSplit validation from buffer apply so the check has no side effects,\nthen take the uring_cmd and store the already-validated buffer. Apply\nthe same order in FETCH so io->buf is not written before __ublk_fetch()\nstate checks."
    }
  ],
  "lastModified": "2026-09-17T17:17:30.307",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}