Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails

sd_set_special_bvec() allocates a special payload page for UNMAP and
WRITE SAME commands. If scsi_alloc_sgtables() fails afterward in
sd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI
midlayer does not call uninit_command() because RQF_DONTPREP is not set
yet, leaking the page.

Call sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after
freeing the page.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak / Memory Leak leading to Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

The vulnerability involves a memory leak in the Linux kernel’s SCSI midlayer. When the scsi_alloc_sgtables() routine fails after an sd_set_special_bvec() call, the special payload page allocated for UNMAP and WRITE SAME commands is not freed because uninit_command() is not invoked and the RQF_SPECIAL_PAYLOAD flag is not cleared. This results in a persistent allocation from the mempool. An attacker who can repeatedly trigger such failures could deplete memory resources, potentially degrading system performance or forcing a reboot. The abuse does not grant code execution; it is a gradual resource exhaustion attack.

Affected Systems

All current Linux kernel releases are potentially impacted until the patch that resolves the mempool leak is applied. The affected product is the Linux kernel; affected versions are unspecified, so all versions before the fix should be considered vulnerable.

Risk and Exploitability

The EPSS score indicates that the probability of exploitation is below 1%, and the vulnerability is not recorded in the CISA KEV catalog, implying no known active exploitation. Nonetheless, the impact of a successful leak can grow over time. The patch fixes the root cause by calling sd_uninit_command() on error and clearing the RQF_SPECIAL_PAYLOAD flag, eliminating the leak. Until the system is patched, the risk remains low to moderate due to the likely local, privileged nature of the triggering SCSI commands and the need for repeated failures to achieve significant impact.

Generated by OpenCVE AI on September 19, 2026 at 04:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the patch for CVE-2026-90267
  • If an immediate kernel update is not possible, restrict access to SCSI commands that use UNMAP and WRITE SAME operations or otherwise limit the ability of untrusted users to issue them
  • Monitor system memory usage for abnormal leaks of special payload pages and ensure that the mempool does not grow without bound

Generated by OpenCVE AI on September 19, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails sd_set_special_bvec() allocates a special payload page for UNMAP and WRITE SAME commands. If scsi_alloc_sgtables() fails afterward in sd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI midlayer does not call uninit_command() because RQF_DONTPREP is not set yet, leaking the page. Call sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after freeing the page.
Title scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:02.624Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90267

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:23.250

Modified: 2026-09-17T17:17:23.250

Link: CVE-2026-90267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T10:00:07Z

Weaknesses

No weakness.