Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: bsg: Fix TOCTOU in io_uring passthrough command setup

scsi_bsg_uring_cmd() reads bsg_uring_cmd from the shared mmap'd SQE.
Userspace can change a field after we check it and before we use it.
request_len is the sharp case: it can grow past sizeof(scmd->cmnd) after
the bound check and overflow scmd->cmnd in copy_from_user().

READ_ONCE() the SQE fields we check or use into locals before use.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a time‑of‑check to time‑of‑use race in the Linux kernel’s SCSI BSG interface that is used through the io_uring API. During a passthrough operation the kernel reads a BSG command structure from a shared memory submission queue element, checks its fields, and then copies user data into a kernel buffer without re‑verifying the size after the check. An attacker can modify the request_len field between the check and the copy, allowing the length to exceed the allocated command buffer and overflow the kernel’s memory. The overflow can corrupt kernel memory and potentially allow the attacker to execute arbitrary code or gain elevated privileges. The flaw therefore enables remote code execution if a local user can send specially crafted commands through io_uring.

Affected Systems

Any Linux kernel that exposes the SCSI BSG interface via io_uring without the reported fix is affected. This includes all distribution kernels that have not applied the commit or any later backport of the patch. If a system’s user land environment can interact with the BSG interface through io_uring, the kernel may be vulnerable, regardless of the distribution or specific kernel release. Patching the kernel to include the safer implementation resolves the issue.

Risk and Exploitability

The CVSS score of 7.8 places the vulnerability in the high severity range. An EPSS score of less than 1% suggests that it is not widely exploited at present, and the vulnerability is not listed in CISA’s KEV catalog. However, the local user can trigger the flaw by sending a crafted BSG command through io_uring and then altering the request length after the initial check but before the data copy. Although no public exploit exists yet, the potential for remote code execution from a local attacker warrants prompt remediation.

Generated by OpenCVE AI on September 18, 2026 at 07:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that includes commit 4b3c5965fca99f62d31c963294bd5b23cc488e97 (or f033530105aa73d82c121d54b57f358e4865d2f4) which secures the io_uring BSG command setup.
  • If an immediate kernel update is not possible, unload or disable the BSG module or block the block SCSI generic interface to prevent user‑supplied SCSI commands from being routed through io_uring; consider configuring access control such as restricting /dev/bsg/* or using a kernel module blacklist.
  • Monitor kernel logs (e.g., dmesg, /var/log/kern.log) for suspicious SCSI command patterns or repeated io_uring submissions that may indicate an attempt to exploit the vulnerability, and isolate affected applications.

Generated by OpenCVE AI on September 18, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-364

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Fix TOCTOU in io_uring passthrough command setup scsi_bsg_uring_cmd() reads bsg_uring_cmd from the shared mmap'd SQE. Userspace can change a field after we check it and before we use it. request_len is the sharp case: it can grow past sizeof(scmd->cmnd) after the bound check and overflow scmd->cmnd in copy_from_user(). READ_ONCE() the SQE fields we check or use into locals before use.
Title scsi: bsg: Fix TOCTOU in io_uring passthrough command setup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:25.065Z

Reserved: 2026-09-11T19:38:34.781Z

Link: CVE-2026-90009

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:13.553

Modified: 2026-09-16T15:18:24.553

Link: CVE-2026-90009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:45:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-364

    Signal Handler Race Condition