CVE-2026-90202
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers _base_release_memory_pools() unconditionally frees every ioc->pcie_sg_lookup[] entry, including ones the setup loop never allocated after a partial failure, causing a "bad dma" warning on debug kernels or a NULL pointer dereference otherwise.
Is your site exposed to CVE-2026-90202?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/240b582b6372bebb1245d911add9954b7dd6c02d
https://git.kernel.org/stable/c/2dbdd025b228110ccbfbab95fe16e098313a14af
https://git.kernel.org/stable/c/3361709fb6f6568b157c6f24ed21a4a5d86d73db
https://git.kernel.org/stable/c/a61181f9ee30a98d2350c1bff32954a7521f9a23
https://git.kernel.org/stable/c/afedf35df054bd713e9e13771aa0a056932c5c67
https://git.kernel.org/stable/c/b9f679dfe629004b593f018df33b330d799bcee4
https://git.kernel.org/stable/c/bc3398db3b64729b4a7907af317daad04795ad40
https://git.kernel.org/stable/c/e2cd23443d3616ea0876f27762b17e2ec67d896c
Frequently Asked Questions
What is CVE-2026-90202? +
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers
_base_release_memory_pools() unconditionally frees every
ioc->pcie_sg_lookup[] entry, including ones the setup loop never
allocated after a partial failure, causing a "bad dma" warning on debug
kernels or a NULL pointer dereference otherwise.
How do I check if I'm vulnerable to CVE-2026-90202? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.