Answer in brief
CVE-2026-90150 records a Unknown severity vulnerability in pnfs/blocklayout: Fix device leaks on parse failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5c83746a0cf2831d4b59f5cf99ef5fbf138564e4 <8a2494964edac2a13e82441c2bf887548dc3be0b || >=5c83746a0cf2831d4b59f5cf99ef5fbf138564e4 <1e1c36b206c659cf94c6755a1d821ed1babd32bc || >=5c83746a0cf2831d4b59f5cf99ef5fbf138564e4 <23e4162405c456ce12c772d5882d306135e828ae || >=5c83746a0cf2831d4b59f5cf99ef5fbf138564e4 <c056f817e4200fb18079d5052c273a22f191ff0a | 8a2494964edac2a13e82441c2bf887548dc3be0b, 1e1c36b206c659cf94c6755a1d821ed1babd32bc, 23e4162405c456ce12c772d5882d306135e828ae, c056f817e4200fb18079d5052c273a22f191ff0a |
| Linux/Linuxgeneric | 3.18 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: pnfs/blocklayout: Fix device leaks on parse failure bl_parse_concat() and bl_parse_stripe() allocate a child device array and then parse each child in turn. If parsing a child fails, the failed child is not counted in nr_children and the parent may be left with a children array that bl_free_device() will not release when nr_children is zero. Release the failed child and the already parsed children before returning the error. Also make bl_free_device() release the child array whenever the children pointer is set, so that partially initialised concat or stripe devices are cleaned up correctly. bl_parse_scsi() can also fail after assigning d->bdev_file and dropping the file reference. Clear the pointer after fput() so that an outer cleanup path does not put it again.
Quoted source text, attributed separately from HOL analysis.