CVE-2026-90007
HIGH
Published Sep 16, 2026
Modified Sep 16, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Use rollback index when freeing MSI-X vectors pm8001_request_msix() unwinds previously registered handlers with free_irq() when request_irq() fails. The rollback loop uses the failing index i for every iteration instead of the already registered vector index j. That passes the wrong IRQ/dev_id pair to free_irq() and leaves the earlier handlers installed. Use j for both pci_irq_vector() and the matching irq_vector entry in the rollback loop.
Is your site exposed to CVE-2026-90007?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Other References
https://git.kernel.org/stable/c/0205db768570f9a46b20912afa581a0c7a63d8b7
https://git.kernel.org/stable/c/2853ce9c88e0e6dd575f95f28b3a8c2b27164115
https://git.kernel.org/stable/c/3f92a64545165bdbb36dee8fa35626b295463313
https://git.kernel.org/stable/c/a980dec7c69990e4f119bcf6a2ea093d1c4975e8
https://git.kernel.org/stable/c/dd817463c9b42a3a9e23d15b86c6c77a6cfb809d
https://git.kernel.org/stable/c/e20b16aa3b49f9db5510940740255a987e6f2a6f
https://git.kernel.org/stable/c/f39e3ca1f688d7c08954a0794e9bf1e279c83b15
https://git.kernel.org/stable/c/fb22a8d2f3ac6665cc8bee197096b6675cac1a9f
Frequently Asked Questions
What is CVE-2026-90007? +
In the Linux kernel, the following vulnerability has been resolved:
scsi: pm8001: Use rollback index when freeing MSI-X vectors
pm8001_request_msix() unwinds previously registered handlers with
free_irq() when request_irq() fails. The rollback loop uses the failing
index i for every iteration instead of the already registered vector
index j.
That passes the wrong IRQ/dev_id pair to free_irq() and leaves the
earlier handlers installed. Use j for both pci_irq_vector() and the
matching irq_vector entry in the rollback loop. It has a CVSS v3.1 base score of 7.8 (HIGH).
How severe is CVE-2026-90007? +
CVE-2026-90007 has a CVSS v3.1 score of 7.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
How do I check if I'm vulnerable to CVE-2026-90007? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.