Race condition in Linux kernel - CVE-2026-90310
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the xenbus_dev_changed() handling of otherend_id when a xenstore watch is processed concurrently with initial device probing. A local user can trigger concurrent xenstore watch processing during device initialization to cause a denial of service.