{"id":"CVE-2026-90267","published":"2026-09-17T17:17:23.250","lastModified":"2026-09-17T17:17:23.250","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails\n\nsd_set_special_bvec() allocates a special payload page for UNMAP and\nWRITE SAME commands. If scsi_alloc_sgtables() fails afterward in\nsd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI\nmidlayer does not call uninit_command() because RQF_DONTPREP is not set\nyet, leaking the page.\n\nCall sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after\nfreeing the page.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/5d7d1b8b525e5eff33a01d07dfcf7bdd3b6d790d","tags":[]},{"url":"https://git.kernel.org/stable/c/bb31844d88b77138b67aa20c3600203baff40140","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}