Linux Kernel Vulnerability in Megaraid Driver Affects NVMe Request Handling
CVE-2026-90008

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90008?

A significant vulnerability exists in the Linux kernel's megaraid_sas driver concerning the handling of NVMe request sizes. This flaw can lead to a buffer overrun due to improper validation of the command's PRP list, which is built without enforcing boundary checks on the DMA pool buffer. When the buffer limit is exceeded, it risks corrupting adjacent memory spaces that may be associated with other active commands. This behavior can potentially lead to system instability and data corruption, emphasizing the critical importance of applying available patches to mitigate these risks.

Affected Version(s)

Linux 9b8b84879d4adc506b0d3944e20b28d9f3f6994b < 4bb34769ef44ab3770b89e4055de6af4a458bec9

Linux 9b8b84879d4adc506b0d3944e20b28d9f3f6994b < 4dd118d06dec9efe5065ac7897bdc18f404a3af4

Linux 9b8b84879d4adc506b0d3944e20b28d9f3f6994b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.