PT-2026-94759 · Linux · Linux Kernel

CVE-2026-90411

·

Published

2026-09-17

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the nvme fc init request() function where the system maps cmd iu and then rsp iu for Direct Memory Access (DMA), a process that allows hardware to access system memory independently of the CPU. If the rsp iu mapping fails, the system fails to unmap the previously mapped cmd iu and incorrectly marks the operation as FCPOP STATE IDLE. Because the block multi-queue (blk-mq) does not call .exit request() upon an .init request() failure, the cmd iu mapping is leaked for every operation where the rsp iu mapping fails.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102372
CVE-2026-90411
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel