{"id":"CVE-2026-90010","published":"2026-09-16T11:17:13.660","lastModified":"2026-09-16T15:18:24.657","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: bsg: Cap io_uring sense copy to max_response_len\n\nCompletion copied scmd->sense_len to the user response buffer without\nhonoring max_response_len. After a valid sense, the midlayer sets\nsense_len to the real length (up to SCSI_SENSE_BUFFERSIZE), so a smaller\nuser buffer was overrun.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/5d326efc334ea21afd8161f6ca53e17de71948a9","tags":[]},{"url":"https://git.kernel.org/stable/c/ece06de726737e887dc0225c8283477624f8ae21","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}