{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90007","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.781Z","datePublished":"2026-09-16T10:33:16.098Z","dateUpdated":"2026-09-16T14:41:21.926Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:41:21.926Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm8001: Use rollback index when freeing MSI-X vectors\n\npm8001_request_msix() unwinds previously registered handlers with\nfree_irq() when request_irq() fails. The rollback loop uses the failing\nindex i for every iteration instead of the already registered vector\nindex j.\n\nThat passes the wrong IRQ/dev_id pair to free_irq() and leaves the\nearlier handlers installed. Use j for both pci_irq_vector() and the\nmatching irq_vector entry in the rollback loop."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in pm8001_request_msix() on the PCI SAS HBA probe and resume path (pm8001_pci_probe/pm8001_pci_resume → pm8001_alloc/pm8001_request_irq), not in network, FC, or USB packet processing; PMC-Sierra/Microchip/ATTO/Adaptec SPCv controllers are local PCI devices in storage servers and workstations.\nAC:L - Once request_irq() fails after any earlier MSI-X vector succeeded, rollback always free_irq()s the failing index i instead of registered index j, then pci_free_irq_vectors() and kfree of the HBA; a local attacker can induce that partial failure with memory or IRQ exhaustion and does not depend on an uncontrolled race.\nPR:L - An unprivileged local user on a machine with a multi-vector SPCv pm8001 HBA can apply memory pressure during probe, deferred probe, or resume so a later request_irq() fails, then spray the heap against the leftover IRQ handler; PCI bind/unbind needs init-namespace root but is not required to exploit the planted UAF.\nUI:N - No victim must mount a filesystem, open a device, or plug hardware; the attacker induces the MSI-X request failure and consumes the leftover handler without another user's action.\nS:U - The leftover irqaction and use-after-free of pm8001_hba_info stay in the host kernel IRQ/SCSI path and do not cross a VM, IOMMU, or other security-authority boundary.\nC:H - Failed MSI-X registration leaves pm8001_interrupt_handler_msix installed with dev_id pointing into pm8001_ha, which pm8001_free() then kfree()s, a use-after-free that per kernel CNA guidance enables arbitrary kernel memory disclosure via slab reuse.\nI:H - The same dangling MSI-X handler reads irq_vector->drv_inst and invokes isr/tasklet on the freed HBA object; reclaiming that heap allocation yields write and control-flow hijack primitives, so integrity impact is High.\nA:H - Wrong-index free_irq() hits WARN on an already-free IRQ, pci_free_irq_vectors() tears down descriptors with live irqactions, and a later IRQ or panic_on_warn can oops or panic the kernel, fully denying availability."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/pm8001/pm8001_init.c"],"versions":[{"version":"a76037ff3479ad333a2505061915f7a21e7f3fb6","lessThan":"f39e3ca1f688d7c08954a0794e9bf1e279c83b15","status":"affected","versionType":"git"},{"version":"a76037ff3479ad333a2505061915f7a21e7f3fb6","lessThan":"a980dec7c69990e4f119bcf6a2ea093d1c4975e8","status":"affected","versionType":"git"},{"version":"a76037ff3479ad333a2505061915f7a21e7f3fb6","lessThan":"0205db768570f9a46b20912afa581a0c7a63d8b7","status":"affected","versionType":"git"},{"version":"a76037ff3479ad333a2505061915f7a21e7f3fb6","lessThan":"2853ce9c88e0e6dd575f95f28b3a8c2b27164115","status":"affected","versionType":"git"},{"version":"a76037ff3479ad333a2505061915f7a21e7f3fb6","lessThan":"fb22a8d2f3ac6665cc8bee197096b6675cac1a9f","status":"affected","versionType":"git"},{"version":"a76037ff3479ad333a2505061915f7a21e7f3fb6","lessThan":"dd817463c9b42a3a9e23d15b86c6c77a6cfb809d","status":"affected","versionType":"git"},{"version":"a76037ff3479ad333a2505061915f7a21e7f3fb6","lessThan":"e20b16aa3b49f9db5510940740255a987e6f2a6f","status":"affected","versionType":"git"},{"version":"a76037ff3479ad333a2505061915f7a21e7f3fb6","lessThan":"3f92a64545165bdbb36dee8fa35626b295463313","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/pm8001/pm8001_init.c"],"versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.11","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f39e3ca1f688d7c08954a0794e9bf1e279c83b15"},{"url":"https://git.kernel.org/stable/c/a980dec7c69990e4f119bcf6a2ea093d1c4975e8"},{"url":"https://git.kernel.org/stable/c/0205db768570f9a46b20912afa581a0c7a63d8b7"},{"url":"https://git.kernel.org/stable/c/2853ce9c88e0e6dd575f95f28b3a8c2b27164115"},{"url":"https://git.kernel.org/stable/c/fb22a8d2f3ac6665cc8bee197096b6675cac1a9f"},{"url":"https://git.kernel.org/stable/c/dd817463c9b42a3a9e23d15b86c6c77a6cfb809d"},{"url":"https://git.kernel.org/stable/c/e20b16aa3b49f9db5510940740255a987e6f2a6f"},{"url":"https://git.kernel.org/stable/c/3f92a64545165bdbb36dee8fa35626b295463313"}],"title":"scsi: pm8001: Use rollback index when freeing MSI-X vectors","x_generator":{"engine":"bippy-1.2.0"}}}}