CVE-2026-90285
Last modified
CVE-2026-90285 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path qla2x00_sysfs_read_vpd() called ha->isp_ops->read_optrom() a second time after releasing optrom_mutex. The repeated read is redundant and, unlike the first, runs without optrom_mutex held, exposing flash access to concurrent optrom operations.
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path qla2x00_sysfs_read_vpd() called ha->isp_ops->read_optrom() a second time after releasing optrom_mutex. The repeated read is redundant and, unlike the first, runs without optrom_mutex held, exposing flash access to concurrent optrom operations. Drop the duplicate call.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 5fa8774c7f38c79f38b672c1a0db0c049da477d6, < ea79c01ef23c2ec3ace8a98ada517d56763814c2; >= 5fa8774c7f38c79f38b672c1a0db0c049da477d6, < beaf45d9a10e7c1de86dcd1cbc8dc17f930444f7; >= 5fa8774c7f38c79f38b672c1a0db0c049da477d6, < abe224e7077ae5d47f1208430ede4d99ae310627; >= 5fa8774c7f38c79f38b672c1a0db0c049da477d6, < 9b6325fc58ab877ecb97fc5642a39e071c343315; >= 5fa8774c7f38c79f38b672c1a0db0c049da477d6, < 95e1ad3f19dfec09eb4f4273cf7079fd9b35cee6; >= 5fa8774c7f38c79f38b672c1a0db0c049da477d6, < 067504c00fe175864652764308922d99e199828f; >= 5fa8774c7f38c79f38b672c1a0db0c049da477d6, < 0e4b5f8cad67eabf98da3f90b6443dcea5783ff3; >= 5fa8774c7f38c79f38b672c1a0db0c049da477d6, < 5cbc49d5c4cd20c18041e86958103045216d2190 |
| Linux | Linux | 5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90285?
How severe is CVE-2026-90285?
How do I fix CVE-2026-90285?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9028The CorvusPay WooCommerce Payment Gateway plugin for WordPre…5.3
- CVE-2026-90280In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90281In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90282In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90283In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90284In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90286In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-90287In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90288In the Linux kernel, the following vulnerability has been re…7.4
- CVE-2026-90289In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-9029A user with Editor permissions can place a malicious script …5.4
- CVE-2026-90290In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-90285?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
