PT-2026-94498 · Linux · Linux Kernel

CVE-2026-90150

·

Published

2026-09-17

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description Device leaks occur during parse failures within the pnfs/blocklayout component. The functions bl parse concat() and bl parse stripe() allocate a child device array and parse each child sequentially; however, if a child fails to parse, it is not included in the nr children count. This can result in the parent retaining a children array that bl free device() fails to release when nr children is zero. Additionally, bl parse scsi() may fail after assigning d->bdev file and dropping the file reference, potentially leading to double-putting the reference during cleanup if the pointer is not cleared after fput().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102081
CVE-2026-90150
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel