CVE-2026-90007
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: pm8001: Use rollback index when freeing MSI-X vectors
pm8001_request_msix() unwinds previously registered handlers with free_irq() when request_irq() fails. The rollback loop uses the failing index i for every iteration instead of the already registered vector index j.
That passes the wrong IRQ/dev_id pair to free_irq() and leaves the earlier handlers installed. Use j for both pci_irq_vector() and the matching irq_vector entry in the rollback loop.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a76037ff3479ad333a2505061915f7a21e7f3fb6 < f39e3ca1f688d7c08954a0794e9bf1e279c83b15 | affected |
| Linux | Linux | a76037ff3479ad333a2505061915f7a21e7f3fb6 < a980dec7c69990e4f119bcf6a2ea093d1c4975e8 | affected |
| Linux | Linux | a76037ff3479ad333a2505061915f7a21e7f3fb6 < 0205db768570f9a46b20912afa581a0c7a63d8b7 | affected |
| Linux | Linux | a76037ff3479ad333a2505061915f7a21e7f3fb6 < 2853ce9c88e0e6dd575f95f28b3a8c2b27164115 | affected |
| Linux | Linux | a76037ff3479ad333a2505061915f7a21e7f3fb6 < fb22a8d2f3ac6665cc8bee197096b6675cac1a9f | affected |
| Linux | Linux | a76037ff3479ad333a2505061915f7a21e7f3fb6 < dd817463c9b42a3a9e23d15b86c6c77a6cfb809d | affected |
| Linux | Linux | a76037ff3479ad333a2505061915f7a21e7f3fb6 < e20b16aa3b49f9db5510940740255a987e6f2a6f | affected |
| Linux | Linux | a76037ff3479ad333a2505061915f7a21e7f3fb6 < 3f92a64545165bdbb36dee8fa35626b295463313 | affected |
| Linux | Linux | 4.11 | affected |
| Linux | Linux | 0 < 4.11 | unaffected |
| Linux | Linux | 5.10.270 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.221 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.188 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.157 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/f39e3ca1f688d7c08954a0794e9bf1e279c83b15
- https://git.kernel.org/stable/c/a980dec7c69990e4f119bcf6a2ea093d1c4975e8
- https://git.kernel.org/stable/c/0205db768570f9a46b20912afa581a0c7a63d8b7
- https://git.kernel.org/stable/c/2853ce9c88e0e6dd575f95f28b3a8c2b27164115
- https://git.kernel.org/stable/c/fb22a8d2f3ac6665cc8bee197096b6675cac1a9f
- https://git.kernel.org/stable/c/dd817463c9b42a3a9e23d15b86c6c77a6cfb809d
- https://git.kernel.org/stable/c/e20b16aa3b49f9db5510940740255a987e6f2a6f
- https://git.kernel.org/stable/c/3f92a64545165bdbb36dee8fa35626b295463313
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.