Answer in brief
CVE-2026-90127 records a Unknown severity vulnerability in virtio: rtc: time out alarm requests. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=9d4f22fd563e0cd02e8448e84d057e7c0132a586 <28701b74c22d2a43ddf7aebb6378e60c18323865 || >=9d4f22fd563e0cd02e8448e84d057e7c0132a586 <afbf69d1d691c06d093d7c3f17168ecb608c4977 || >=9d4f22fd563e0cd02e8448e84d057e7c0132a586 <68e00d9212929805b40dcb9166755610f4f4acee | 28701b74c22d2a43ddf7aebb6378e60c18323865, afbf69d1d691c06d093d7c3f17168ecb608c4977, 68e00d9212929805b40dcb9166755610f4f4acee |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio: rtc: time out alarm requests RTC class operations run with rtc_device.ops_lock held. The virtio RTC alarm requests currently wait without a timeout for the device to return their requestq buffers. On surprise removal, virtio-pci marks the virtqueues broken before unregistering the virtio device. If an alarm request is waiting when the device stops responding, viortc_remove() blocks in viortc_class_stop() while trying to acquire ops_lock. The request cannot complete and device removal hangs until the waiting task is signalled. Use the same 60-second timeout as clock read requests for alarm reads, alarm programming, and alarm interrupt enable requests. The existing message reference counting keeps a timed-out request alive until a late response or device teardown.
Quoted source text, attributed separately from HOL analysis.