CVE-2026-90128

Source
https://cve.org/CVERecord?id=CVE-2026-90128
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90128.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90128
Downstream
Published
2026-09-17T16:06:29Z
Modified
2026-09-19T03:47:28Z
Summary
vdpa/mlx5: fix wrong list iterated in add_direct_chain error path
Details

In the Linux kernel, the following vulnerability has been resolved:

vdpa/mlx5: fix wrong list iterated in add_direct_chain error path

In add_direct_chain(), newly allocated direct MR entries are added to the local list 'tmp', which is spliced into mr->head only on success. On the error path, the cleanup loop was incorrectly iterating over mr->head instead of tmp.

Fix by iterating over 'tmp' in the err_alloc cleanup path.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90128.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
94abbccdf2916cb03f9626f2d36c6e9971490c12
Fixed
c93defccf5eb0a92bdafa43487be6ce0221a2477
Fixed
ed3462365636df3bc63e34d7468f4faed3f70a4e
Fixed
22d52af9e26a72bdfe2dcfb1419a091de4862cd9
Fixed
eeac2ea4ad2654e3f160a9b608d05c9af31433a6
Fixed
637d867530daea61898e3346975978b7f67fc2ac
Fixed
6ca752850de3b8162f030793cc15001aec85c4cf
Fixed
c678d04ac9e5a64c2559c43bce273e845fbd09eb
Fixed
23ae56d9e74c122f95cae71ae3b9fc259fb88446

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90128.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.9.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90128.json"