Improper resource shutdown or release in Linux kernel - CVE-2026-90268
Published: September 18, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper resource handling in sd_probe() when probing a SCSI device with a sector size larger than the page size and large pool creation fails. An attacker with physical access can trigger device probing under these conditions to cause a denial of service.