Improper input validation in Linux kernel - CVE-2026-90232
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the AMT device creation handler (amt_newlink) when configuring an AMT device with a lower device in a different network namespace. A local user can create a cross-network-namespace AMT device and remove its lower device to cause a denial of service.