CVE-2026-90285

Source
https://cve.org/CVERecord?id=CVE-2026-90285
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90285.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90285
Downstream
Published
2026-09-17T16:08:14Z
Modified
2026-09-19T03:47:25Z
Summary
scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path

qla2x00_sysfs_read_vpd() called ha->isp_ops->read_optrom() a second time after releasing optrom_mutex. The repeated read is redundant and, unlike the first, runs without optrom_mutex held, exposing flash access to concurrent optrom operations. Drop the duplicate call.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90285.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5fa8774c7f38c79f38b672c1a0db0c049da477d6
Fixed
ea79c01ef23c2ec3ace8a98ada517d56763814c2
Fixed
beaf45d9a10e7c1de86dcd1cbc8dc17f930444f7
Fixed
abe224e7077ae5d47f1208430ede4d99ae310627
Fixed
9b6325fc58ab877ecb97fc5642a39e071c343315
Fixed
95e1ad3f19dfec09eb4f4273cf7079fd9b35cee6
Fixed
067504c00fe175864652764308922d99e199828f
Fixed
0e4b5f8cad67eabf98da3f90b6443dcea5783ff3
Fixed
5cbc49d5c4cd20c18041e86958103045216d2190

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90285.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90285.json"