CVE-2026-90319
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-90319, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-17
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
rapidio: clear mport->net when rio_add_net() fails
rio_alloc_net() stores the newly allocated rio_net in mport->net before
rio_scan_alloc_net() registers the device.
If rio_add_net() fails, rio_scan_alloc_net() drops the device reference
with put_device(), which releases the rio_net through the device release
callback. However, mport->net is left pointing at the freed object.
A later mport unregister path can then dereference the dangling mport->net
pointer and may try to free the same rio_net again.
Clear mport->net in the rio_add_net() failure path, matching the cleanup
done for the destID table allocation failure path.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 4f3509cfcc02e9d757f2714bb7dbbeec35de6fa7 |
| Linux | Linux | 181d4daaefb3bceeb2f2635ba9f3781eeda9e550 |
| Linux | Linux | ad82be4298a89a9ae46f07128bdf3d8614bce745 |
| Linux | Linux | e6411c3b9512dba09af7d014d474516828c89706 |
| Linux | Linux | c332f3e2df0fcae5a45fd55cc18902fb1e4825ca |
| Linux | Linux | e842f9a1edf306bf36fe2a4d847a0b0d458770de |
| Linux | Linux | e842f9a1edf306bf36fe2a4d847a0b0d458770de |
| Linux | Linux | e842f9a1edf306bf36fe2a4d847a0b0d458770de |
| Linux | Linux | 6d22953c4a183d0b7fdf34d68c5debd16da6edc5 |
| Linux | Linux | a0d069ccc475abaaa79c6368ee27fc0b5912bea8 |
| Linux | Linux | 5.10.235 |
| Linux | Linux | 5.15.179 |
| Linux | Linux | 6.1.131 |
| Linux | Linux | 6.6.83 |
| Linux | Linux | 6.12.19 |
| Linux | Linux | 5.4.291 |
| Linux | Linux | 6.13.7 |
| Linux | Linux | 6.14 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |