Improper input validation in Linux kernel - CVE-2026-90323
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the UBLK io_uring command handling when processing automatic buffer registration data from a submission queue entry. A local user can submit an io_uring command with invalid automatic buffer registration data to cause a teardown hang.