CVE-2026-90128
In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: fix wrong list iterated in add_direct_chain error path In add_direct_chain(), newly allocated direct MR entries are added to the local list 'tmp', which is spliced into mr->head only on success. On the error path, the cleanup loop was incorrectly iterating over mr->head instead of tmp. Fix by iterating over 'tmp' in the err_alloc cleanup path.
Affected versions
Linux kernel versions
5.9
and later are affected. Fixed in
5.10.270,
5.15.221,
6.1.188,
6.6.157,
6.12.110,
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
8 totalFrequently asked questions
-
What is CVE-2026-90128?
CVE-2026-90128 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.9 onward and has been patched in 5.10.270, 5.15.221, 6.1.188 and others. CVE-2026-90128 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-90128?
Yes. CVE-2026-90128 has been patched. Fixed versions include 5.10.270, 5.15.221, 6.1.188 and others. If you are running Linux kernel 5.9 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-90128 actively exploited?
No. CVE-2026-90128 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.