CVE-2026-90128

medium

Description

In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: fix wrong list iterated in add_direct_chain error path In add_direct_chain(), newly allocated direct MR entries are added to the local list 'tmp', which is spliced into mr->head only on success. On the error path, the cleanup loop was incorrectly iterating over mr->head instead of tmp. Fix by iterating over 'tmp' in the err_alloc cleanup path.

References

https://git.kernel.org/stable/c/eeac2ea4ad2654e3f160a9b608d05c9af31433a6

https://git.kernel.org/stable/c/ed3462365636df3bc63e34d7468f4faed3f70a4e

https://git.kernel.org/stable/c/c93defccf5eb0a92bdafa43487be6ce0221a2477

https://git.kernel.org/stable/c/c678d04ac9e5a64c2559c43bce273e845fbd09eb

https://git.kernel.org/stable/c/6ca752850de3b8162f030793cc15001aec85c4cf

https://git.kernel.org/stable/c/637d867530daea61898e3346975978b7f67fc2ac

https://git.kernel.org/stable/c/23ae56d9e74c122f95cae71ae3b9fc259fb88446

https://git.kernel.org/stable/c/22d52af9e26a72bdfe2dcfb1419a091de4862cd9

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.0021