CVE-2026-90411

Source
https://cve.org/CVERecord?id=CVE-2026-90411
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90411.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90411
Downstream
Published
2026-09-17T16:09:38Z
Modified
2026-09-18T03:48:38Z
Summary
nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request
Details

In the Linux kernel, the following vulnerability has been resolved:

nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request

__nvme_fc_init_request() maps cmd_iu and then rsp_iu for DMA. If the rsp_iu mapping fails, the original code only recorded the error and fell through: it left the already-mapped cmd_iu unmapped and still marked the op as FCPOP_STATE_IDLE before returning. Since blk-mq does not call .exit_request() when .init_request() fails, the cmd_iu mapping is leaked for every op whose rsp_iu mapping fails.

Jump to an error path on rsp_iu mapping failure that unmaps cmd_iu and returns the error without marking the op idle, so it stays in the FCPOP_STATE_UNINIT state set by the initial memset().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90411.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e399441de9115cd472b8ace6c517708273ca7997
Fixed
c0892cfb60a75e2c86ba8e2127b133f6549c12b3
Fixed
5e820d04c241c81a47e1940349018690e93d8167
Fixed
bb0251991420c25e3ceeac40ea09250d79ed7ef0
Fixed
acc173608ca7abe5dee8983086b44efd8b0dbc84
Fixed
18c5781ed8bc2f423c26ec93e47e2057cd76a783
Fixed
bd764baf82bb46e958a0bd0b481630dd71313055
Fixed
be5eb47ee3fea338efae1a5b678d6bb5f0fcc931
Fixed
f49d0c3a8d56a7cda1628ae17341a4a42063563c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90411.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90411.json"