{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90268","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.796Z","datePublished":"2026-09-17T16:08:03.312Z","dateUpdated":"2026-09-18T17:54:15.152Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:15.152Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: sd: Fix error handling in sd_probe() after large pool creation failure\n\nAfter device_add(&sdkp->disk_dev) succeeds, sd_large_pool_create()\nfailure must unregister disk_dev and let scsi_disk_release() free\nsdkp. Going through out_free_index kfree()s an already registered device\nand leaks the sysfs entry."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - After iscsi_scan_session()->scsi_scan_target()->scsi_probe_and_add_lun() binds TYPE_DISK, sd_probe()->sd_revalidate_disk()->read_capacity_16() takes the Logical Block Length from the target’s READ CAPACITY(16) Data-In at buffer[8] (or READ CAPACITY(10) at buffer[4]) over iSCSI TCP; that value is what enters the sd_large_pool_create() error path.\nAC:H - The bad goto is taken only when sd_large_page_pool is still NULL and mempool_create_page_pool(SD_MEMPOOL_SIZE=2, get_order(BLK_MAX_BLOCK_SIZE)) fails its GFP_KERNEL order-4 preallocation of two 64K pages; a remote target cannot force that allocator failure or whether an earlier large-sector disk already created the pool.\nPR:N - The attacker is the iSCSI target supplying INQUIRY PDT=TYPE_DISK and the READ CAPACITY block length during automatic LUN scan; scsi_bus_probe()->sd_probe() runs on the initiator with no capability check against the target, and iSCSI is commonly deployed without CHAP.\nUI:N - Once the session is ISCSI_SESSION_LOGGED_IN, iscsi_scan_session work calls scsi_scan_target, which invokes sd_probe and sd_revalidate_disk with no open(), mount, or operator action; the target alone presents the LUN and the capacity response.\nS:U - kfree(sdkp) while sdkp->disk_dev remains registered after device_add() corrupts only the initiator kernel’s device-model/sysfs state for that scsi_disk; it does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - out_free_index kfree()s the scsi_disk that embeds the still-registered disk_dev, so later sysfs reads of sd_disk_groups attributes via to_scsi_disk() and scsi_disk_release() operate on a freed heap object, giving a use-after-free read primitive.\nI:H - The same kfree leaves disk_dev, gd->private_data, and the sdev drvdata set by dev_set_drvdata() pointing at freed sdkp; writable scsi_disk sysfs stores and scsi_disk_release()’s second kfree/ida_free then write through that UAF, enabling heap corruption and control-flow hijack.\nA:H - Use-after-free of the registered scsi_disk, including scsi_disk_release() running on already-freed memory (double-free of sdkp and a second ida_free of sdkp->index), oopses or panics when udev, sysfs, or parent sdev removal touches disk_dev."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/sd.c"],"versions":[{"version":"7179e626b76eb42f2529c6f6dd6ba88ea2445372","lessThan":"748a14a0d41cfe3017251c11b314f85045414942","status":"affected","versionType":"git"},{"version":"7179e626b76eb42f2529c6f6dd6ba88ea2445372","lessThan":"e3cc6ea1a745e7f5d326f919a428b244fa119d8f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/sd.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/748a14a0d41cfe3017251c11b314f85045414942"},{"url":"https://git.kernel.org/stable/c/e3cc6ea1a745e7f5d326f919a428b244fa119d8f"}],"title":"scsi: sd: Fix error handling in sd_probe() after large pool creation failure","x_generator":{"engine":"bippy-1.2.0"}}}}