CVE-2026-90085

Source
https://cve.org/CVERecord?id=CVE-2026-90085
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90085.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90085
Downstream
Published
2026-09-17T16:06:01Z
Modified
2026-09-18T03:48:35Z
Summary
octeontx2-af: fix NULL deref in NIX TM tree debugfs read path
Details

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-af: fix NULL deref in NIX TM tree debugfs read path

rvu_dbg_nix_tm_tree_display() dereferences pfvf->sq_ctx without checking whether the SQ context has been allocated. Reading /sys/kernel/debug/octeontx2/nix/tm_tree for a NIX LF whose transmit queues are not set up triggers a kernel oops.

Guard the read path the same way rvu_dbg_nix_tm_tree_write() already does and return -EINVAL with a seq_file message when sq_ctx is NULL.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90085.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b907194a5d5bcd3b01d28d095f6a4d9fcd9c5354
Fixed
fb736d733b0a60377cf53010571c261886446fd5
Fixed
537e11a1700f64dc6754108f0e1333ad63d4f548
Fixed
fdf7358e2688f12eff41290bc45030b7aff0845e
Fixed
ec65631bd5ec251cdf67a4919fac7a3149a6e235

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90085.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90085.json"