CVE-2026-90158
Last modified
CVE-2026-90158 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list synchronization") show_cons_active() calls the .device() method under the console_list_lock, but console_is_registered() tries to acquire console_list_lock as well, causing a deadlock. It should not be necessary to check console_is_registered() here since the function should not be called in the fist place when the console is not registered..
Description
In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list synchronization") show_cons_active() calls the .device() method under the console_list_lock, but console_is_registered() tries to acquire console_list_lock as well, causing a deadlock. It should not be necessary to check console_is_registered() here since the function should not be called in the fist place when the console is not registered.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < 7d3f15a664d115584fc177b5f2cfbdb3e5a50d60; >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < e5e11274b5512e24a346ed83f8dd85e3389d2f4b; >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < be98f92fc244688a6bdecbc834cf2cd243056d9d; >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < d73441232f1f067eb659e94447b1353c16609711; >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < 2f8e3cad53b5c36ab0ed5d3195bfc55c59ea61a5 |
| Linux | Linux | 6.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90158?
How severe is CVE-2026-90158?
How do I fix CVE-2026-90158?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90152In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90153In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-90154In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90155In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90156In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90157In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90159In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9016The Debug Log Manager – Conveniently Monitor and Inspect Err…5.3
- CVE-2026-90160In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90161In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-90162In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-90163In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-90158?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
