Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: sd: Fix error handling in sd_probe() after large pool creation failure

After device_add(&sdkp->disk_dev) succeeds, sd_large_pool_create()
failure must unregister disk_dev and let scsi_disk_release() free
sdkp. Going through out_free_index kfree()s an already registered device
and leaks the sysfs entry.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and potential kernel memory corruption
Action: Apply patch
AI Analysis

Impact

The Linux kernel contains a bug in the SCSI disk driver where failure to create a large memory pool during device probing can cause the kernel to unregister and free a device that is still registered. This leads to a kfree of a live device reference and leaves a broken sysfs entry, potentially triggering a kernel panic or memory corruption. The effect is a denial of service and, because the fault occurs in kernel space, it could allow a local attacker to gain elevated privileges or execute arbitrary code if they can force the failure path.

Affected Systems

The flaw resides in the Linux kernel’s SCSI subsystem and affects any Linux system running a kernel version that includes the vulnerable sd_probe() implementation. No version range is specified, so any distribution that has not yet applied the fix is potentially impacted.

Risk and Exploitability

With a CVSS score of 8.1 the vulnerability is considered high impact, but its EPSS score of less than 1% indicates that exploitation has not yet been observed in the wild. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is local, requiring an attacker to manipulate SCSI device creation or trigger large pool allocation failures, which may be feasible for privileged or unprivileged users on systems with exposed SCSI disks.

Generated by OpenCVE AI on September 19, 2026 at 15:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update containing the SD probe error handling fix
  • If an immediate update is not possible, disable the large pool creation feature for SCSI devices or restrict access to SCSI device configuration from untrusted users
  • Enable kernel hardening options such as CONFIG_STRICT_DEVMEM and SELinux/AppArmor to limit the impact of any remaining memory‑corrupting bugs

Generated by OpenCVE AI on September 19, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-567

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix error handling in sd_probe() after large pool creation failure After device_add(&sdkp->disk_dev) succeeds, sd_large_pool_create() failure must unregister disk_dev and let scsi_disk_release() free sdkp. Going through out_free_index kfree()s an already registered device and leaks the sysfs entry.
Title scsi: sd: Fix error handling in sd_probe() after large pool creation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:15.152Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90268

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:23.360

Modified: 2026-09-18T18:17:51.443

Link: CVE-2026-90268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-416

    Use After Free

  • CWE-567

    Unsynchronized Access to Shared Data in a Multithreaded Context