CVE-2026-90009
CVE CVE-2026-90009EUVD EUVD-2026-80617Published 2026-09-16T10:33:17.000ZLast changed 2026-09-16T14:41:25.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Fix TOCTOU in io_uring passthrough command setup scsi_bsg_uring_cmd() reads bsg_uring_cmd from the shared mmap'd SQE. Userspace can change a field after we check it and before we use it. request_len is the sharp case: it can grow past sizeof(scmd->cmnd) after the bound check and overflow scmd->cmnd in copy_from_user(). READ_ONCE() the SQE fields we check or use into locals before use.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 7b6d3255e7f8c6df2d21504c47808e3ce84649ac <4b3c5965fca99f62d31c963294bd5b23cc488e97; patch: 0; patch: 7.3-rc2; patch: 7.2.5; 7.1; 7b6d3255e7f8c6df2d21504c47808e3ce84649ac <f033530105aa73d82c121d54b57f358e4865d2f4
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.