Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: bsg: Cap io_uring sense copy to max_response_len

Completion copied scmd->sense_len to the user response buffer without
honoring max_response_len. After a valid sense, the midlayer sets
sense_len to the real length (up to SCSI_SENSE_BUFFERSIZE), so a smaller
user buffer was overrun.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Buffer overflow leading to arbitrary memory corruption
Action: Immediate Patch
AI Analysis

Impact

A Linux kernel flaw in the SCSI block layer can cause an unchecked copy of a SCSI sense buffer into a user‑supplied response buffer. The kernel copies the full sense_len, up to SCSI_SENSE_BUFFERSIZE, without respecting the supplied max_response_len. This results in a classic buffer overflow that may corrupt adjacent memory and potentially allow a privileged or local attacker to execute code, crash the system, or perform other destructive actions. The weakness is a classic Buffer Overflow (CWE‑119).

Affected Systems

The vulnerability applies to all releases of the Linux kernel; vendors Linux:Linux are affected. No specific version range is listed, so any kernel without the patch is vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS of less than 1% suggests a low probability of exploitation at the time of analysis, and the vulnerability is not yet listed in CISA KEV. The attack is most likely a local one, though a remote attacker might trigger the SCSI command path via networked SCSI subsystems. No additional exploitation conditions are disclosed in the description.

Generated by OpenCVE AI on September 18, 2026 at 07:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that contains the fix for this SCSI buffer overflow
  • Restrict or disable the BSG interface for untrusted processes so that only privileged entities can issue SCSI commands
  • Ensure that any application that uses io_uring with SCSI sense data validates the size of the user buffers before passing them to the kernel

Generated by OpenCVE AI on September 18, 2026 at 07:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Cap io_uring sense copy to max_response_len Completion copied scmd->sense_len to the user response buffer without honoring max_response_len. After a valid sense, the midlayer sets sense_len to the real length (up to SCSI_SENSE_BUFFERSIZE), so a smaller user buffer was overrun.
Title scsi: bsg: Cap io_uring sense copy to max_response_len
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:26.660Z

Reserved: 2026-09-11T19:38:34.781Z

Link: CVE-2026-90010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:13.660

Modified: 2026-09-16T15:18:24.657

Link: CVE-2026-90010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer