CVE-2026-90158
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list synchronization") show_cons_active() calls the .device() method under the console_list_lock, but console_is_registered() tries to acquire console_list_lock as well, causing a deadlock. It should not be necessary to check console_is_registered() here since the function should not be called in the fist place when the console is not registered.
Is your site exposed to CVE-2026-90158?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/2f8e3cad53b5c36ab0ed5d3195bfc55c59ea61a5
https://git.kernel.org/stable/c/7d3f15a664d115584fc177b5f2cfbdb3e5a50d60
https://git.kernel.org/stable/c/be98f92fc244688a6bdecbc834cf2cd243056d9d
https://git.kernel.org/stable/c/d73441232f1f067eb659e94447b1353c16609711
https://git.kernel.org/stable/c/e5e11274b5512e24a346ed83f8dd85e3389d2f4b
Frequently Asked Questions
What is CVE-2026-90158? +
In the Linux kernel, the following vulnerability has been resolved:
m68k: nfcon: Do not call console_is_registered() in nfcon_device()
Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list
synchronization") show_cons_active() calls the .device() method under
the console_list_lock, but console_is_registered() tries to acquire
console_list_lock as well, causing a deadlock. It should not be
necessary to check console_is_registered() here since the function
should not be called in the fist place when the console is not
registered.
How do I check if I'm vulnerable to CVE-2026-90158? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.