CVE-2026-90128
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: fix wrong list iterated in add_direct_chain error path In add_direct_chain(), newly allocated direct MR entries are added to the local list 'tmp', which is spliced into mr->head only on success. On the error path, the cleanup loop was incorrectly iterating over mr->head instead of tmp. Fix by iterating over 'tmp' in the err_alloc cleanup path.
Is your site exposed to CVE-2026-90128?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/22d52af9e26a72bdfe2dcfb1419a091de4862cd9
https://git.kernel.org/stable/c/23ae56d9e74c122f95cae71ae3b9fc259fb88446
https://git.kernel.org/stable/c/637d867530daea61898e3346975978b7f67fc2ac
https://git.kernel.org/stable/c/6ca752850de3b8162f030793cc15001aec85c4cf
https://git.kernel.org/stable/c/c678d04ac9e5a64c2559c43bce273e845fbd09eb
https://git.kernel.org/stable/c/c93defccf5eb0a92bdafa43487be6ce0221a2477
https://git.kernel.org/stable/c/ed3462365636df3bc63e34d7468f4faed3f70a4e
https://git.kernel.org/stable/c/eeac2ea4ad2654e3f160a9b608d05c9af31433a6
Frequently Asked Questions
What is CVE-2026-90128? +
In the Linux kernel, the following vulnerability has been resolved:
vdpa/mlx5: fix wrong list iterated in add_direct_chain error path
In add_direct_chain(), newly allocated direct MR entries are added to
the local list 'tmp', which is spliced into mr->head only on success.
On the error path, the cleanup loop was incorrectly iterating over
mr->head instead of tmp.
Fix by iterating over 'tmp' in the err_alloc cleanup path.
How do I check if I'm vulnerable to CVE-2026-90128? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.