Answer in brief
CVE-2026-90191 records a Unknown severity vulnerability in mailbox: riscv-sbi-mpxy: validate RPMI notification lengths. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 <cbc24bce70dfd91c7b2f53b4fa896e9a4b6d6a6b || >=bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 <c7bc5e7677bcda7a446d63b989cfaa3fe91d6b76 || >=bf3022a4eb119c6b4e3424d6b19d8bfdfbc9bb57 <11d5af151bcbe78f5a579e0faecd3be9cea0399a | cbc24bce70dfd91c7b2f53b4fa896e9a4b6d6a6b, c7bc5e7677bcda7a446d63b989cfaa3fe91d6b76, 11d5af151bcbe78f5a579e0faecd3be9cea0399a |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: mailbox: riscv-sbi-mpxy: validate RPMI notification lengths The SBI return value controls how many bytes are copied from shared memory into the RPMI notification buffer. It is not validated against the negotiated shared-memory size before that copy. The event walker also uses a reversed loop condition and can inspect a short event record. Validate the complete notification length before copying it, iterate only while a full event header remains, and stop when a declared event payload extends beyond the copied notification data.
Quoted source text, attributed separately from HOL analysis.