Improper resource shutdown or release in Linux kernel - CVE-2026-90015
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to cause data corruption and leak DMA mappings.
The vulnerability exists due to improper handling of bounce buffers in the xHCI transfer descriptor bounce-buffer cleanup logic when processing sufficiently large fragmented bulk USB transfers that span multiple ring segments. A local user can submit a crafted bulk transfer to cause data corruption and leak DMA mappings.
For IN transfers, unreturned bounce-buffer data can leave a wMaxPacketSize-sized region of the destination buffer containing its previous contents.
Affected software
How to mitigate CVE-2026-90015
External References
- https://git.kernel.org/stable/c/3c9a2b5a4f1183696f02ac280ced1d34afb409b1
- https://git.kernel.org/stable/c/43239fc6dfb62c50ae1b9c0e82bac0f8cd2e285c
- https://git.kernel.org/stable/c/7236bbd2cb7d9fc0eda896bbd34790341e2a4377
- https://git.kernel.org/stable/c/a1629dfb011446d02905778f6df19f14c5f4f3b3
- https://git.kernel.org/stable/c/c8124b28f12dbdd126118e63d0ebf8093a01fb81
- https://git.kernel.org/stable/c/e04d5304a248e5d2a7f4faa87541644bdd320cfb
- https://git.kernel.org/stable/c/efaab8938fb92979be6df359f7d1a43fb7e4717d
- https://git.kernel.org/stable/c/ff44dfb03a293bf30e31f98772a1dd316a6071d1