PT-2026-94576 · Linux · Linux Kernel

CVE-2026-90228

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference occurs in the nvmet execute identify ns zns() function. This happens when a host sends an Identify command with CNS 05h and CSI 02h (ZNS) targeting a file-backed namespace. Because file-backed namespaces lack a block device, the req->ns->bdev variable is NULL. When the system calls bdev is zoned() using this NULL variable, it causes a system crash (oops). This issue is triggered whenever CONFIG BLK DEV ZONED is enabled, regardless of the namespace backing type.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102158
CVE-2026-90228
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel