Race condition in Linux kernel - CVE-2026-90206
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause memory corruption.
The vulnerability exists due to a race condition in NVMe target controller allocation when changing a subsystem's max_qid limit during controller allocation. A local privileged user can concurrently modify the max_qid configuration and allocate a controller to cause memory corruption.