PT-2026-93672 · Linux · Linux Kernel

CVE-2026-90031

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the usb-storage module specifically affecting ene ub6250. The ene ub6250 probe() function calls usb stor probe2(), which schedules delayed scan work. Subsequently, the driver calls ene get card type(), which sends an ENE command via ene send scsi cmd(). Both the delayed scan work (via usb stor Bulk max lun()) and ene get card type() access the us->current urb variable. While the scan work uses us->dev mutex for serialization, ene get card type() does not. If the scan work executes while ene get card type() is utilizing us->current urb, the usb submit urb() function triggers a warning indicating the URB is already active.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101451
CVE-2026-90031
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel