{"id":"CVE-2026-90319","published":"2026-09-17T17:17:29.817","lastModified":"2026-09-17T17:17:29.817","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrapidio: clear mport->net when rio_add_net() fails\n\nrio_alloc_net() stores the newly allocated rio_net in mport->net before\nrio_scan_alloc_net() registers the device.\n\nIf rio_add_net() fails, rio_scan_alloc_net() drops the device reference\nwith put_device(), which releases the rio_net through the device release\ncallback.  However, mport->net is left pointing at the freed object.\n\nA later mport unregister path can then dereference the dangling mport->net\npointer and may try to free the same rio_net again.\n\nClear mport->net in the rio_add_net() failure path, matching the cleanup\ndone for the destID table allocation failure path.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/24f60ebabeb8757cec8ec2f97660d521bc9147ec","tags":[]},{"url":"https://git.kernel.org/stable/c/332591a245de978349a7558f8b20469951bb77cc","tags":[]},{"url":"https://git.kernel.org/stable/c/3f00999e44d9984036a029dbad9d2afe94a674d0","tags":[]},{"url":"https://git.kernel.org/stable/c/44a37264b26911e13d0a4f5630751c4157ed0354","tags":[]},{"url":"https://git.kernel.org/stable/c/530a9d5ef831a0049dad9a6b2b92d02301352c38","tags":[]},{"url":"https://git.kernel.org/stable/c/6a760a53e73064735cdfa9e51c664983a89baf96","tags":[]},{"url":"https://git.kernel.org/stable/c/75f0bc167b96bbbef8182b88308c732af82c8d83","tags":[]},{"url":"https://git.kernel.org/stable/c/b74030fbf187b43c1f85b66a7082e9946511cb5d","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}