Description
In the Linux kernel, the following vulnerability has been resolved:

block: mtip32xx: synchronize ioctls with device removal

The ioctl handlers only test REMOVE_PENDING before entering
mtip_hw_ioctl(). Removal can set that bit immediately afterwards and free
dd->port in mtip_hw_exit() while an ioctl still dereferences it. An already
open block device can reach the handlers while del_gendisk() is in
progress.

Serialize both native and compat ioctls with removal. Set REMOVE_PENDING
before taking the mutex so new callers fail after an in-flight ioctl has
drained, and hold the mutex until the port has been torn down.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free that can lead to kernel memory corruption or arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because the ioctl handlers for the mtip32xx block driver only check a pending‑removal flag before calling the core ioctl routine. When a device removal occurs, the flag can be set immediately afterwards and the device’s private data may be freed while an ioctl is still in progress, permitting the handler to dereference freed memory. This use‑after‑free can corrupt kernel memory and potentially allow an attacker with local access to execute arbitrary kernel code or cause a denial of service.

Affected Systems

All Linux kernel systems that load the mtip32xx block driver are affected. The vulnerability exists in kernel versions before the commit that synchronizes IOCTLs with device removal; specific affected versions are not listed.

Risk and Exploitability

The EPSS score of less than 1 % indicates the likelihood of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided, but the use‑after‑free flaw suggests a high severity if exploited. Attackers would need local or privileged access to perform the vulnerable ioctl while the device is being removed, making this a local‑scope risk.

Generated by OpenCVE AI on September 20, 2026 at 02:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the 4609e0e0, 521afbd9 or later commits that synchronize IOCTLs with device removal.
  • Before removing an mtip32xx device, ensure no ioctl requests are in flight by pausing user operations and waiting for all in‑flight IOCTLS to complete.
  • If a patched kernel is not yet available, temporarily unload or blacklist the mtip32xx driver so the device cannot be accessed until the kernel is updated.

Generated by OpenCVE AI on September 20, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: block: mtip32xx: synchronize ioctls with device removal The ioctl handlers only test REMOVE_PENDING before entering mtip_hw_ioctl(). Removal can set that bit immediately afterwards and free dd->port in mtip_hw_exit() while an ioctl still dereferences it. An already open block device can reach the handlers while del_gendisk() is in progress. Serialize both native and compat ioctls with removal. Set REMOVE_PENDING before taking the mutex so new callers fail after an in-flight ioctl has drained, and hold the mutex until the port has been torn down.
Title block: mtip32xx: synchronize ioctls with device removal
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:05.083Z

Reserved: 2026-09-11T19:38:34.791Z

Link: CVE-2026-90180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:12.123

Modified: 2026-09-17T17:17:12.123

Link: CVE-2026-90180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:17Z

Weaknesses