Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel - CVE-2026-90009
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service and compromise confidentiality and integrity.
The vulnerability exists due to a time-of-check to time-of-use race condition in scsi_bsg_uring_cmd() when processing io_uring passthrough commands from a shared memory-mapped submission queue entry. A local user can modify the request length after validation to overflow scmd->cmnd during copy_from_user() and cause a denial of service and compromise confidentiality and integrity.