CVE-2026-90267

Summary

In the Linux kernel, the following vulnerability has been resolved:

scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails

sd_set_special_bvec() allocates a special payload page for UNMAP and WRITE SAME commands. If scsi_alloc_sgtables() fails afterward in sd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI midlayer does not call uninit_command() because RQF_DONTPREP is not set yet, leaking the page.

Call sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after freeing the page.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux81d926e8b5520e38f1f72dd7bb7cfc81c1a69d87 < 5d7d1b8b525e5eff33a01d07dfcf7bdd3b6d790daffected
LinuxLinux81d926e8b5520e38f1f72dd7bb7cfc81c1a69d87 < bb31844d88b77138b67aa20c3600203baff40140affected
LinuxLinux4.12affected
LinuxLinux0 < 4.12unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References