Improper access control in Linux kernel - CVE-2026-90315
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to bypass kernel lockdown PCI access restrictions.
The vulnerability exists due to improper access control in the legacy PCI sysfs I/O and memory handlers when accessing legacy I/O and memory spaces while the kernel is locked down. A local privileged user can write arbitrary I/O ports and map legacy I/O and memory spaces to bypass kernel lockdown PCI access restrictions.