CVE-2026-90411
In the Linux kernel, the following vulnerability has been resolved:
nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request
__nvme_fc_init_request() maps cmd_iu and then rsp_iu for DMA. If the rsp_iu mapping fails, the original code only recorded the error and fell through: it left the already-mapped cmd_iu unmapped and still marked the op as FCPOP_STATE_IDLE before returning. Since blk-mq does not call .exit_request() when .init_request() fails, the cmd_iu mapping is leaked for every op whose rsp_iu mapping fails.
Jump to an error path on rsp_iu mapping failure that unmaps cmd_iu and returns the error without marking the op idle, so it stays in the FCPOP_STATE_UNINIT state set by the initial memset().
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/18c5781ed8bc2f423c26ec93e47e2057cd76a783
- https://git.kernel.org/stable/c/5e820d04c241c81a47e1940349018690e93d8167
- https://git.kernel.org/stable/c/acc173608ca7abe5dee8983086b44efd8b0dbc84
- https://git.kernel.org/stable/c/bb0251991420c25e3ceeac40ea09250d79ed7ef0
- https://git.kernel.org/stable/c/bd764baf82bb46e958a0bd0b481630dd71313055
- https://git.kernel.org/stable/c/be5eb47ee3fea338efae1a5b678d6bb5f0fcc931
- https://git.kernel.org/stable/c/c0892cfb60a75e2c86ba8e2127b133f6549c12b3
- https://git.kernel.org/stable/c/f49d0c3a8d56a7cda1628ae17341a4a42063563c
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90411",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e399441de9115cd472b8ace6c517708273ca7997",
"lessThan": "c0892cfb60a75e2c86ba8e2127b133f6549c12b3",
"versionType": "git"
},
{
"status": "affected",
"version": "e399441de9115cd472b8ace6c517708273ca7997",
"lessThan": "5e820d04c241c81a47e1940349018690e93d8167",
"versionType": "git"
},
{
"status": "affected",
"version": "e399441de9115cd472b8ace6c517708273ca7997",
"lessThan": "bb0251991420c25e3ceeac40ea09250d79ed7ef0",
"versionType": "git"
},
{
"status": "affected",
"version": "e399441de9115cd472b8ace6c517708273ca7997",
"lessThan": "acc173608ca7abe5dee8983086b44efd8b0dbc84",
"versionType": "git"
},
{
"status": "affected",
"version": "e399441de9115cd472b8ace6c517708273ca7997",
"lessThan": "18c5781ed8bc2f423c26ec93e47e2057cd76a783",
"versionType": "git"
},
{
"status": "affected",
"version": "e399441de9115cd472b8ace6c517708273ca7997",
"lessThan": "bd764baf82bb46e958a0bd0b481630dd71313055",
"versionType": "git"
},
{
"status": "affected",
"version": "e399441de9115cd472b8ace6c517708273ca7997",
"lessThan": "be5eb47ee3fea338efae1a5b678d6bb5f0fcc931",
"versionType": "git"
},
{
"status": "affected",
"version": "e399441de9115cd472b8ace6c517708273ca7997",
"lessThan": "f49d0c3a8d56a7cda1628ae17341a4a42063563c",
"versionType": "git"
}
],
"programFiles": [
"drivers/nvme/host/fc.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/nvme/host/fc.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:41.077",
"references": [
{
"url": "https://git.kernel.org/stable/c/18c5781ed8bc2f423c26ec93e47e2057cd76a783",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5e820d04c241c81a47e1940349018690e93d8167",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/acc173608ca7abe5dee8983086b44efd8b0dbc84",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bb0251991420c25e3ceeac40ea09250d79ed7ef0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bd764baf82bb46e958a0bd0b481630dd71313055",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/be5eb47ee3fea338efae1a5b678d6bb5f0fcc931",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c0892cfb60a75e2c86ba8e2127b133f6549c12b3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f49d0c3a8d56a7cda1628ae17341a4a42063563c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request\n\n__nvme_fc_init_request() maps cmd_iu and then rsp_iu for DMA. If the\nrsp_iu mapping fails, the original code only recorded the error and fell\nthrough: it left the already-mapped cmd_iu unmapped and still marked the\nop as FCPOP_STATE_IDLE before returning. Since blk-mq does not call\n.exit_request() when .init_request() fails, the cmd_iu mapping is leaked\nfor every op whose rsp_iu mapping fails.\n\nJump to an error path on rsp_iu mapping failure that unmaps cmd_iu and\nreturns the error without marking the op idle, so it stays in the\nFCPOP_STATE_UNINIT state set by the initial memset()."
}
],
"lastModified": "2026-09-17T17:17:41.077",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}