CVE-2026-90158

Unknown

Last modified

CVE-2026-90158 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list synchronization") show_cons_active() calls the .device() method under the console_list_lock, but console_is_registered() tries to acquire console_list_lock as well, causing a deadlock. It should not be necessary to check console_is_registered() here since the function should not be called in the fist place when the console is not registered..

Description

In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list synchronization") show_cons_active() calls the .device() method under the console_list_lock, but console_is_registered() tries to acquire console_list_lock as well, causing a deadlock. It should not be necessary to check console_is_registered() here since the function should not be called in the fist place when the console is not registered.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < 7d3f15a664d115584fc177b5f2cfbdb3e5a50d60; >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < e5e11274b5512e24a346ed83f8dd85e3389d2f4b; >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < be98f92fc244688a6bdecbc834cf2cd243056d9d; >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < d73441232f1f067eb659e94447b1353c16609711; >= 7c2af0f634f1bc761ca827310dc7e8e586af502f, < 2f8e3cad53b5c36ab0ed5d3195bfc55c59ea61a5
LinuxLinux6.2

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90158?
In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list synchronization") show_cons_active() calls the .device() method under the console_list_lock, but console_is_registered() tries to acquire console_list_lock as well, causing a deadlock. It should not be necessary to check console_is_registered() here since the function should not be called in the fist place when the console is not registered.
How severe is CVE-2026-90158?
Severity scoring for CVE-2026-90158 is pending analysis.
How do I fix CVE-2026-90158?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90158?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST