Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-90348
Published: September 18, 2026
Vulnerability identifier: #VU151136
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90348
CWE-ID: CWE-754
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to improper handling of device-memory mappings in ath10k_msa_dump_memory() when collecting an MSA firmware crash dump. A local privileged user can cause firmware crash dump collection to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-90348
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/045d1bfb72d2631ab9ec74afa491aa788ebb57aa
- https://git.kernel.org/stable/c/152e894e90716163c646d70f86b3afeb70442783
- https://git.kernel.org/stable/c/4f25071afe9218aaae1c63fbf75e229aa6405319
- https://git.kernel.org/stable/c/7039825a7479df637c4f5d546cb0e1cec18cd8e1
- https://git.kernel.org/stable/c/838cab267ce9a975776e022f25094f8cbe1625d2
- https://git.kernel.org/stable/c/e5bc3658da9c8a535e3fa5c0c875b2a456954e81
- https://git.kernel.org/stable/c/eb946595a58decdb4cab1b5f3c972ae66f41f1c8
- https://git.kernel.org/stable/c/fed1f662c9f9fd19eeab6c01966b7b5a33804420