CVE-2026-90290

Source
https://cve.org/CVERecord?id=CVE-2026-90290
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90290.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90290
Downstream
Published
2026-09-17T16:08:18Z
Modified
2026-09-19T03:47:25Z
Summary
arm64: hibernate: Restore DAIF state on error
Details

In the Linux kernel, the following vulnerability has been resolved:

arm64: hibernate: Restore DAIF state on error

Sashiko AI has reported that if swsusp_mte_save_tags() for some reason fails we return from swsusp_arch_suspend() with DAIF being masked - that is not what we'd expect. Restore the saved DAIF state before returning from the error path.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90290.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ee11f332af96a3b5d29586bc6d69b41531f62648
Fixed
f5693dfaf28d66e7e880feafd1778d3715869efc
Fixed
2c941f383a53e188cd6fe3a129eb9b52b298e683
Fixed
cb51a05498e755d900900ff4b8503b4da4325996
Fixed
ad3839fe2114bb092846df79edd8d119e148b8c3
Fixed
c8c6835f62a7f9fc68865e85397d13a2dc9210fb
Fixed
519e7de2c4c7b92ef57d4404b7e564aa9be24143
Fixed
77053624d03359a4e2ec47d7106639ec9a498c2b
Fixed
541549827889d0380fd73f8aacb5de6ef7a5a1ac

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90290.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90290.json"