CVE-2026-90180

Unknown

Last modified

CVE-2026-90180 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: block: mtip32xx: synchronize ioctls with device removal The ioctl handlers only test REMOVE_PENDING before entering mtip_hw_ioctl(). Removal can set that bit immediately afterwards and free dd->port in mtip_hw_exit() while an ioctl still dereferences it.

Description

In the Linux kernel, the following vulnerability has been resolved: block: mtip32xx: synchronize ioctls with device removal The ioctl handlers only test REMOVE_PENDING before entering mtip_hw_ioctl(). Removal can set that bit immediately afterwards and free dd->port in mtip_hw_exit() while an ioctl still dereferences it. An already open block device can reach the handlers while del_gendisk() is in progress. Serialize both native and compat ioctls with removal. Set REMOVE_PENDING before taking the mutex so new callers fail after an in-flight ioctl has drained, and hold the mutex until the port has been torn down.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 88523a61558a040546bf7d8b079ae0755d8e7005, < 521afbd936ac256b7531470b0b9aa96abf9cd853; >= 88523a61558a040546bf7d8b079ae0755d8e7005, < 8283049aa5fcb4e84b2b2928b2888903bb8ee12e; >= 88523a61558a040546bf7d8b079ae0755d8e7005, < 8a7799597bd683b6bc251fe2edfa9fd1db568a3a; >= 88523a61558a040546bf7d8b079ae0755d8e7005, < 4609e0e0be709e974bec9b52c5022136d25e97d3; >= 88523a61558a040546bf7d8b079ae0755d8e7005, < b389dc35a55713ac24a145741e76196fea1663bc; >= 88523a61558a040546bf7d8b079ae0755d8e7005, < 68940f841d013192086a0f6d7cfbac2cd079e228
LinuxLinux3.3

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90180?
In the Linux kernel, the following vulnerability has been resolved: block: mtip32xx: synchronize ioctls with device removal The ioctl handlers only test REMOVE_PENDING before entering mtip_hw_ioctl(). Removal can set that bit immediately afterwards and free dd->port in mtip_hw_exit() while an ioctl still dereferences it. An already open block device can reach the handlers while del_gendisk() is in progress. Serialize both native and compat ioctls with removal. Set REMOVE_PENDING before taking the mutex so new callers fail after an in-flight ioctl has drained, and hold the mutex until the port has been torn down.
How severe is CVE-2026-90180?
Severity scoring for CVE-2026-90180 is pending analysis.
How do I fix CVE-2026-90180?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90180?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST