CVE-2026-90180 PUBLISHED

block: mtip32xx: synchronize ioctls with device removal

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

block: mtip32xx: synchronize ioctls with device removal

The ioctl handlers only test REMOVE_PENDING before entering mtip_hw_ioctl(). Removal can set that bit immediately afterwards and free dd->port in mtip_hw_exit() while an ioctl still dereferences it. An already open block device can reach the handlers while del_gendisk() is in progress.

Serialize both native and compat ioctls with removal. Set REMOVE_PENDING before taking the mutex so new callers fail after an in-flight ioctl has drained, and hold the mutex until the port has been torn down.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 88523a61558a040546bf7d8b079ae0755d8e7005 to 521afbd936ac256b7531470b0b9aa96abf9cd853 (excl.)
  • affected from 88523a61558a040546bf7d8b079ae0755d8e7005 to 8283049aa5fcb4e84b2b2928b2888903bb8ee12e (excl.)
  • affected from 88523a61558a040546bf7d8b079ae0755d8e7005 to 8a7799597bd683b6bc251fe2edfa9fd1db568a3a (excl.)
  • affected from 88523a61558a040546bf7d8b079ae0755d8e7005 to 4609e0e0be709e974bec9b52c5022136d25e97d3 (excl.)
  • affected from 88523a61558a040546bf7d8b079ae0755d8e7005 to b389dc35a55713ac24a145741e76196fea1663bc (excl.)
  • affected from 88523a61558a040546bf7d8b079ae0755d8e7005 to 68940f841d013192086a0f6d7cfbac2cd079e228 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.3 is affected
  • unaffected from 0 to 3.3 (excl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References