Answer in brief
CVE-2026-90388 records a Unknown severity vulnerability in iommu/dma: Check atomic pool allocation result directly. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=9420139f516d7fbc248ce17f35275cb005ed98ea <ac9cd0a669b8be5d178dbd471b0d68039dac58b5 || >=9420139f516d7fbc248ce17f35275cb005ed98ea <db46cb9da83a507d86d2bb080bdb09c865da3d0a || >=9420139f516d7fbc248ce17f35275cb005ed98ea <d56c3f955b21e5764c1497e295a5b5d0b3a40470 || >=9420139f516d7fbc248ce17f35275cb005ed98ea <06dffc96693083dda3412311406e558cf27f1574 || >=9420139f516d7fbc248ce17f35275cb005ed98ea <a4ace31d732b657d774e31fb444c0c27d42c78e5 || >=9420139f516d7fbc248ce17f35275cb005ed98ea <fb0b39287ba894dbdfac2901c51788b63f5c2291 || >=9420139f516d7fbc248ce17f35275cb005ed98ea <8c486293ddd0af60991408149fc3e964ea888dc4 || >=9420139f516d7fbc248ce17f35275cb005ed98ea <af95a0ebc0a0db0762be75f51eadf770bad01aaa || 47184b9ddf184cc9a77cf441943a0fe9b7afa575 || >=5.8.6 <5.9 | ac9cd0a669b8be5d178dbd471b0d68039dac58b5, db46cb9da83a507d86d2bb080bdb09c865da3d0a, d56c3f955b21e5764c1497e295a5b5d0b3a40470, 06dffc96693083dda3412311406e558cf27f1574, a4ace31d732b657d774e31fb444c0c27d42c78e5, fb0b39287ba894dbdfac2901c51788b63f5c2291, 8c486293ddd0af60991408149fc3e964ea888dc4, af95a0ebc0a0db0762be75f51eadf770bad01aaa, 5.9 |
| Linux/Linuxgeneric | 5.9 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Check atomic pool allocation result directly The non-blocking, non-coherent allocation path uses dma_alloc_from_pool(), which returns the allocated page and fills cpu_addr only on success. Do not rely on cpu_addr to detect allocation failure in this path. Check the returned page directly before using it for the IOMMU mapping.
Quoted source text, attributed separately from HOL analysis.