CVE-2026-90324 PUBLISHED

ublk: check import_ubuf() return value

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ublk: check import_ubuf() return value

import_ubuf() can fail if the address range (provided by the userspace ublk server) is outside the allowed user address space. Return that 0 bytes were copied if import_ubuf() fails rather than passing an uninitialized struct iov_iter to ublk_copy_user_pages().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 981f95a571e3ca20a496c0b77dbf6b06039c6648 to 0121c84adb6a4cd6f7560b5895bd88f9899bbc1f (excl.)
  • affected from 981f95a571e3ca20a496c0b77dbf6b06039c6648 to 5ac6019cb78e98c9608fda72726b36ddf8474dd7 (excl.)
  • affected from 981f95a571e3ca20a496c0b77dbf6b06039c6648 to 3831568792af75b6523fa93bb91560e29189cf55 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.5 is affected
  • unaffected from 0 to 6.5 (excl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References