Answer in brief
CVE-2026-90107 records a Unknown severity vulnerability in net/smc: free pending qentry in smc_llc_flow_stop() before memset. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=555da9af827d95134656fa459c8f3ece04dd867a <8e3deb150a5237b672c4579e69a6deb02027dbed || >=555da9af827d95134656fa459c8f3ece04dd867a <11bc373ee6630709f0c2da2e7860c23d503c9e9d || >=555da9af827d95134656fa459c8f3ece04dd867a <032aec7d03c9102616b98fea74f8f7145e7f867c || >=555da9af827d95134656fa459c8f3ece04dd867a <957dba2b8b5aebfe09caa6a6b22b958079082eab || >=555da9af827d95134656fa459c8f3ece04dd867a <f03aa5d36ae3c4068a1c3885146be99aa7fd9307 || >=555da9af827d95134656fa459c8f3ece04dd867a <0879ea157acc1ac6752f6fcb755d1f91a2359238 || >=555da9af827d95134656fa459c8f3ece04dd867a <5ff429dd6725fa6c1e17a4ed0be8ab675f67a98b || >=555da9af827d95134656fa459c8f3ece04dd867a <5ee0ceddc7785c6dcf4a8107fef01f0414a354f4 | 8e3deb150a5237b672c4579e69a6deb02027dbed, 11bc373ee6630709f0c2da2e7860c23d503c9e9d, 032aec7d03c9102616b98fea74f8f7145e7f867c, 957dba2b8b5aebfe09caa6a6b22b958079082eab, f03aa5d36ae3c4068a1c3885146be99aa7fd9307, 0879ea157acc1ac6752f6fcb755d1f91a2359238, 5ff429dd6725fa6c1e17a4ed0be8ab675f67a98b, 5ee0ceddc7785c6dcf4a8107fef01f0414a354f4 |
| Linux/Linuxgeneric | 5.8 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: net/smc: free pending qentry in smc_llc_flow_stop() before memset smc_llc_flow_stop() resets a flow struct with a blind memset: spin_lock_bh(&lgr->llc_flow_lock); memset(flow, 0, sizeof(*flow)); flow->type = SMC_LLC_FLOW_NONE; spin_unlock_bh(&lgr->llc_flow_lock); If flow->qentry is non-NULL at this point the pointer is overwritten without the allocation being freed, leaking one kmalloc object. A late-arriving duplicate CONFIRM_LINK or ADD_LINK_CONT message can set flow->qentry after the legitimate message has been consumed by the waiter via smc_llc_flow_qentry_clr() (which NULLs the pointer but leaves flow->type non-zero) but before the flow completes and smc_llc_flow_stop() runs. In that window the duplicate is stashed into flow->qentry, and then lost when smc_llc_flow_stop() zeros the struct. Call smc_llc_flow_qentry_del() inside the lock before the memset. smc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the normal case where no entry is pending is a no-op.
Quoted source text, attributed separately from HOL analysis.