{"id":"CVE-2026-90323","published":"2026-09-17T17:17:30.307","lastModified":"2026-09-17T17:17:30.307","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nublk: validate auto buf reg before taking uring_cmd\n\nWith UBLK_F_AUTO_BUF_REG, invalid sqe->addr can fail after\nublk_fill_io_cmd() has set UBLK_IO_FLAG_ACTIVE. The uring_cmd is\ncompleted while the tag stays active, which can hang teardown.\n\nSplit validation from buffer apply so the check has no side effects,\nthen take the uring_cmd and store the already-validated buffer. Apply\nthe same order in FETCH so io->buf is not written before __ublk_fetch()\nstate checks.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/653d22269a8b83b491f7f186a5d7872f14e6ddca","tags":[]},{"url":"https://git.kernel.org/stable/c/ca5a01eee34c7cbe0f531a613b0292a3ad1a419b","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}