CVE-2026-90180

Summary

In the Linux kernel, the following vulnerability has been resolved:

block: mtip32xx: synchronize ioctls with device removal

The ioctl handlers only test REMOVE_PENDING before entering mtip_hw_ioctl(). Removal can set that bit immediately afterwards and free dd->port in mtip_hw_exit() while an ioctl still dereferences it. An already open block device can reach the handlers while del_gendisk() is in progress.

Serialize both native and compat ioctls with removal. Set REMOVE_PENDING before taking the mutex so new callers fail after an in-flight ioctl has drained, and hold the mutex until the port has been torn down.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux88523a61558a040546bf7d8b079ae0755d8e7005 < 521afbd936ac256b7531470b0b9aa96abf9cd853affected
LinuxLinux88523a61558a040546bf7d8b079ae0755d8e7005 < 8283049aa5fcb4e84b2b2928b2888903bb8ee12eaffected
LinuxLinux88523a61558a040546bf7d8b079ae0755d8e7005 < 8a7799597bd683b6bc251fe2edfa9fd1db568a3aaffected
LinuxLinux88523a61558a040546bf7d8b079ae0755d8e7005 < 4609e0e0be709e974bec9b52c5022136d25e97d3affected
LinuxLinux88523a61558a040546bf7d8b079ae0755d8e7005 < b389dc35a55713ac24a145741e76196fea1663bcaffected
LinuxLinux88523a61558a040546bf7d8b079ae0755d8e7005 < 68940f841d013192086a0f6d7cfbac2cd079e228affected
LinuxLinux3.3affected
LinuxLinux0 < 3.3unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References