CVE-2026-90209
Last modified
CVE-2026-90209 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix deadlock during unregister Unregistering an s390dbf debug area while one of the associated debugfs files is being written to can cause a deadlock: $ echo >.../vmur/level $ rmmod vmur =================================================== debugfs write debugfs_file_get() debug_unregister() mutex_lock(debug_mutex) debugfs_remove() wait for debugfs_file_put() debug_file_ops.write() debug_input() mutex_lock(debug_mutex) ==> DEADLOCK Fix this by splitting debug_unregister() into an s390dbf and debugfs part, and running only the s390dbf part with debug_mutex locked..
Description
In the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix deadlock during unregister Unregistering an s390dbf debug area while one of the associated debugfs files is being written to can cause a deadlock: $ echo >.../vmur/level $ rmmod vmur =================================================== debugfs write debugfs_file_get() debug_unregister() mutex_lock(debug_mutex) debugfs_remove() wait for debugfs_file_put() debug_file_ops.write() debug_input() mutex_lock(debug_mutex) ==> DEADLOCK Fix this by splitting debug_unregister() into an s390dbf and debugfs part, and running only the s390dbf part with debug_mutex locked.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 9372a82892c2caa6bccab9a4081166fa769699f8, < a214c3dacc779b2afcb0ac9c8001e45ee4ffb2ed; >= 9372a82892c2caa6bccab9a4081166fa769699f8, < 183f8f6d64bb0510070c856b9927618c53014a7b; >= 9372a82892c2caa6bccab9a4081166fa769699f8, < a08b70ed2d1ec907353a72f15163b8e34ff4b2f8; >= 9372a82892c2caa6bccab9a4081166fa769699f8, < 45bb341d1b73eb293e0dd43d9b72bbc8b615d0ba; >= 9372a82892c2caa6bccab9a4081166fa769699f8, < 5d83f3faa3fb7f23f298cfd40382611999de5d1d; >= 9372a82892c2caa6bccab9a4081166fa769699f8, < 54e1259b75d6402a1d0cfb822b9bb2c507e53dab; >= 9372a82892c2caa6bccab9a4081166fa769699f8, < 445c31ac638fd1af203d79bdf25fc0cb3149fbbc; c68ba4a708fbd0efdc384cd29250bb292a45e559; 86f9980909f31ab205323eeeb290fe3cbb4952b4; fe5793e90d3f572a87ba67fe2f0e1679fdff14f8; e234f66168f0d50c0d28154fb983a14e85c3c526; >= 5.4.146, < 5.5; >= 5.10.65, < 5.11; >= 5.13.17, < 5.14; >= 5.14.4, < 5.15 |
| Linux | Linux | 5.15 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90209?
How severe is CVE-2026-90209?
How do I fix CVE-2026-90209?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90203In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-90204In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90205In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90206In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90207In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90208In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9021The Easy Invoice plugin for WordPress is vulnerable to Missi…5.3
- CVE-2026-90210In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90211In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90212In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90213In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90214In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-90209?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
