Out-of-bounds read in Linux kernel - CVE-2026-90145
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to trigger IOMMU faults.
The vulnerability exists due to a stale skb fragment count in hinic3_send_one_skb() TX descriptor construction when processing unsupported tunnel packets that require checksum fallback. A local user can send a specially crafted unsupported tunnel packet to trigger IOMMU faults.