NONE · 0

CVE-2026-90202

In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers _base_release_memory_pools() unconditionally frees every ioc->pcie_sg_lo...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers _base_release_memory_pools() unconditionally frees every ioc->pcie_sg_lookup[] entry, including ones the setup loop never allocated after a partial failure, causing a "bad dma" warning on debug kernels or a NULL pointer dereference otherwise.

References

FAQ

What is CVE-2026-90202?

CVE-2026-90202 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers _base_release_memory_pools() unconditionally frees every ioc->pcie_sg_lo...

How severe is CVE-2026-90202?

CVSS scoring is not yet available for CVE-2026-90202. Check NVD for updates.

Is there a patch for CVE-2026-90202?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.