Infinite loop in Linux kernel - CVE-2026-90391
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper error handling in dmirror_fault() in lib/test_hmm.c when handling dmirror read or write ioctl operations after the mirrored mm has exited. A local user can issue dmirror read or write ioctl operations to cause a denial of service.
The loop is reached after a missing device page table entry is encountered.
Affected software
How to mitigate CVE-2026-90391
External References
- https://git.kernel.org/stable/c/2636569ea7c19d9a40db4a1e8d0a027bdacf1569
- https://git.kernel.org/stable/c/50606ced303782f8715e2d0b98ca374ea498fa29
- https://git.kernel.org/stable/c/541a67f21ab807c8dbc0ea88d5a2eb73b2618090
- https://git.kernel.org/stable/c/6a8024511ddf4877435c34fb3d6028aa8e590649
- https://git.kernel.org/stable/c/701347e31aa607f3782403151a3125729d685275
- https://git.kernel.org/stable/c/a2074f86fc9653831e4fb7b711bb715db330f182
- https://git.kernel.org/stable/c/af7a6d6ec36a16a583ba2e4e9984c3cf1fe34655
- https://git.kernel.org/stable/c/d8e64ffab01e032ae29159d27230ace8cf8bdc80