Answer in brief
CVE-2026-90219 records a Unknown severity vulnerability in RDMA/cxgb4: Free debugfs on registration failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=49ea0c036ede81f126f1a9389d377999fdf5c5a1 <459b59f7ed56511d6529311cb4e5e482ebfcfb8e || >=49ea0c036ede81f126f1a9389d377999fdf5c5a1 <cd60992f09b7e83bfd3c76e3bb06b29f3e2fa0a8 || >=49ea0c036ede81f126f1a9389d377999fdf5c5a1 <c332d9e7dce234d8bef78271d003a68ee943b61b || >=49ea0c036ede81f126f1a9389d377999fdf5c5a1 <f98e894ec029a752cf9c7f7834741bead0fb463d || >=49ea0c036ede81f126f1a9389d377999fdf5c5a1 <479a7f90060e62bdd9bb4036ec0a70bf460f6d23 || >=49ea0c036ede81f126f1a9389d377999fdf5c5a1 <046425412529dbfca1433c8bef5641b271b4ab2a || >=49ea0c036ede81f126f1a9389d377999fdf5c5a1 <ea41b5630fa3d9877ce9ed8832cf5575f742bfbb || >=49ea0c036ede81f126f1a9389d377999fdf5c5a1 <fe5c16bb6252dea6025b748257ddc3b2665495b0 || 98fa991017981b52dcc4dc3924fc8e1e83e41bf4 || af92e4a595e006b498c44b617ea38f697eca3469 || 9c0cec79e5c914662c2cf98b4a729c0fcc8c872e || >=4.19.130 <4.20 || >=5.4.49 <5.5 || >=5.7.6 <5.8 | 459b59f7ed56511d6529311cb4e5e482ebfcfb8e, cd60992f09b7e83bfd3c76e3bb06b29f3e2fa0a8, c332d9e7dce234d8bef78271d003a68ee943b61b, f98e894ec029a752cf9c7f7834741bead0fb463d, 479a7f90060e62bdd9bb4036ec0a70bf460f6d23, 046425412529dbfca1433c8bef5641b271b4ab2a, ea41b5630fa3d9877ce9ed8832cf5575f742bfbb, fe5c16bb6252dea6025b748257ddc3b2665495b0, 4.20, 5.5, 5.8 |
| Linux/Linuxgeneric | 5.8 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Free debugfs on registration failure c4iw_alloc() creates the per-device debugfs tree (dev->debugfs_root via setup_debugfs()), but it is removed only in c4iw_remove(), not in c4iw_dealloc(). When RDMA device registration fails, the registration worker's err_dealloc_ctx path calls c4iw_dealloc() directly, bypassing c4iw_remove(), so the debugfs dentries leak and outlive the freed c4iw_dev. Move debugfs_remove_recursive() into c4iw_dealloc() so every path that frees ctx->dev also removes its debugfs tree.
Quoted source text, attributed separately from HOL analysis.