Buffer Overrun Vulnerability in Linux Kernel SCSI Driver
CVE-2026-90010

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90010?

A buffer overrun vulnerability exists in the SCSI driver of the Linux kernel where the response length for the io_uring completion is incorrectly copied to the user response buffer. This occurs when the actual sense length exceeds the maximum response length, leading to potential overwriting of adjacent memory. The vulnerability could lead to unpredictable behavior, compromise system stability, and pose security risks if exploited. It is crucial to update the affected Linux Kernel versions to ensure system integrity and security.

Affected Version(s)

Linux 7b6d3255e7f8c6df2d21504c47808e3ce84649ac < 5d326efc334ea21afd8161f6ca53e17de71948a9

Linux 7b6d3255e7f8c6df2d21504c47808e3ce84649ac

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.