SCSI Vulnerability in Linux Kernel Affects pm8001 by Linux Foundation
CVE-2026-90007
Currently unrated
What is CVE-2026-90007?
This vulnerability in the Linux kernel's SCSI pm8001 driver arises from improper handling of MSI-X vectors during the IRQ request process. When the request_irq function fails, the pm8001_request_msix function unwinds previously registered IRQ handlers incorrectly, using the wrong index during the rollback process. This may leave earlier handlers still installed, which can lead to unexpected behavior and potential security issues. Correcting this flaw requires utilizing the correct registered vector index throughout the rollback loop.
Affected Version(s)
Linux a76037ff3479ad333a2505061915f7a21e7f3fb6
Linux a76037ff3479ad333a2505061915f7a21e7f3fb6
Linux a76037ff3479ad333a2505061915f7a21e7f3fb6 < 0205db768570f9a46b20912afa581a0c7a63d8b7