Improper handling of exceptional conditions in Linux kernel - CVE-2026-90290
Published: September 18, 2026
Vulnerability identifier: #VU151187
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90290
CWE-ID: CWE-755
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to improper handling of exceptional conditions in swsusp_arch_suspend() when handling a failure from swsusp_mte_save_tags(). A local privileged user can trigger the hibernation error path to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-90290
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/2c941f383a53e188cd6fe3a129eb9b52b298e683
- https://git.kernel.org/stable/c/519e7de2c4c7b92ef57d4404b7e564aa9be24143
- https://git.kernel.org/stable/c/541549827889d0380fd73f8aacb5de6ef7a5a1ac
- https://git.kernel.org/stable/c/77053624d03359a4e2ec47d7106639ec9a498c2b
- https://git.kernel.org/stable/c/ad3839fe2114bb092846df79edd8d119e148b8c3
- https://git.kernel.org/stable/c/c8c6835f62a7f9fc68865e85397d13a2dc9210fb
- https://git.kernel.org/stable/c/cb51a05498e755d900900ff4b8503b4da4325996
- https://git.kernel.org/stable/c/f5693dfaf28d66e7e880feafd1778d3715869efc