{"id":"CVE-2026-90324","published":"2026-09-17T17:17:30.410","lastModified":"2026-09-18T18:17:53.840","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nublk: check import_ubuf() return value\n\nimport_ubuf() can fail if the address range (provided by the userspace\nublk server) is outside the allowed user address space. Return that 0\nbytes were copied if import_ubuf() fails rather than passing an\nuninitialized struct iov_iter to ublk_copy_user_pages().","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/0121c84adb6a4cd6f7560b5895bd88f9899bbc1f","tags":[]},{"url":"https://git.kernel.org/stable/c/3831568792af75b6523fa93bb91560e29189cf55","tags":[]},{"url":"https://git.kernel.org/stable/c/5ac6019cb78e98c9608fda72726b36ddf8474dd7","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}