{"id":"CVE-2026-90007","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm8001: Use rollback index when freeing MSI-X vectors\n\npm8001_request_msix() unwinds previously registered handlers with\nfree_irq() when request_irq() fails","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm8001: Use rollback index when freeing MSI-X vectors\n\npm8001_request_msix() unwinds previously registered handlers with\nfree_irq() when request_irq() fails. The …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= a76037ff3479ad333a2505061915f7a21e7f3fb6 < f39e3ca1f688d7c08954a0794e9bf1e279c83b15","Linux >= a76037ff3479ad333a2505061915f7a21e7f3fb6 < a980dec7c69990e4f119bcf6a2ea093d1c4975e8","Linux >= a76037ff3479ad333a2505061915f7a21e7f3fb6 < 0205db768570f9a46b20912afa581a0c7a63d8b7","Linux >= a76037ff3479ad333a2505061915f7a21e7f3fb6 < 2853ce9c88e0e6dd575f95f28b3a8c2b27164115","Linux >= a76037ff3479ad333a2505061915f7a21e7f3fb6 < fb22a8d2f3ac6665cc8bee197096b6675cac1a9f","Linux >= a76037ff3479ad333a2505061915f7a21e7f3fb6 < dd817463c9b42a3a9e23d15b86c6c77a6cfb809d","Linux >= a76037ff3479ad333a2505061915f7a21e7f3fb6 < e20b16aa3b49f9db5510940740255a987e6f2a6f","Linux >= a76037ff3479ad333a2505061915f7a21e7f3fb6 < 3f92a64545165bdbb36dee8fa35626b295463313","Linux 4.11"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:18:24.297","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90007","references":[{"url":"https://git.kernel.org/stable/c/0205db768570f9a46b20912afa581a0c7a63d8b7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2853ce9c88e0e6dd575f95f28b3a8c2b27164115","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f92a64545165bdbb36dee8fa35626b295463313","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a980dec7c69990e4f119bcf6a2ea093d1c4975e8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd817463c9b42a3a9e23d15b86c6c77a6cfb809d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e20b16aa3b49f9db5510940740255a987e6f2a6f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f39e3ca1f688d7c08954a0794e9bf1e279c83b15","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb22a8d2f3ac6665cc8bee197096b6675cac1a9f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T10:53:53.944Z","epss":0.00176,"epssPercentile":0.06321,"slug":"CVE-2026-90007","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm8001: Use rollback index when freeing MSI-X vectors\n\npm8001_request_msix() unwinds previously registered handlers with\nfree_irq() when request_irq() fails. The rollback loop uses the failing\nindex i for every iteration instead of the already registered vector\nindex j.\n\nThat passes the wrong IRQ/dev_id pair to free_irq() and leaves the\nearlier handlers installed. Use j for both pci_irq_vector() and the\nmatching irq_vector entry in the rollback loop.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":205023,"id":"CVE-2026-90007","ts":1789570704825,"field":"cvss","old":null,"new":"7.8"},{"seq":205022,"id":"CVE-2026-90007","ts":1789570704825,"field":"severity","old":"none","new":"high"}]}