Out-of-bounds write in Linux kernel - CVE-2026-90008
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code, escalate privileges, disclose sensitive information, or cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the megaraid_sas NVMe PRP-list construction routine, megasas_make_prp_nvme(), when processing oversized NVMe transfer requests. A local user can submit an oversized NVMe transfer request to overwrite memory beyond the PRP chain frame and to execute arbitrary code, escalate privileges, disclose sensitive information, or cause a denial of service.
The overflow can corrupt the PRP list of another in-flight command when the adjacent memory is mapped.