CVE-2026-90202

Source
https://cve.org/CVERecord?id=CVE-2026-90202
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90202.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90202
Downstream
Published
2026-09-17T16:07:19Z
Modified
2026-09-19T03:47:30Z
Summary
scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers

_base_release_memory_pools() unconditionally frees every ioc->pcie_sg_lookup[] entry, including ones the setup loop never allocated after a partial failure, causing a "bad dma" warning on debug kernels or a NULL pointer dereference otherwise.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90202.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dbec4c9040edc15442c3ebdb65408aa9d3b82c24
Fixed
3361709fb6f6568b157c6f24ed21a4a5d86d73db
Fixed
240b582b6372bebb1245d911add9954b7dd6c02d
Fixed
a61181f9ee30a98d2350c1bff32954a7521f9a23
Fixed
afedf35df054bd713e9e13771aa0a056932c5c67
Fixed
bc3398db3b64729b4a7907af317daad04795ad40
Fixed
2dbdd025b228110ccbfbab95fe16e098313a14af
Fixed
e2cd23443d3616ea0876f27762b17e2ec67d896c
Fixed
b9f679dfe629004b593f018df33b330d799bcee4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90202.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90202.json"