{"id":"CVE-2026-90391","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nlib/test_hmm: fail dmirror_fault() when the mirrored mm is gone\n\ndmirror_fault() is called from the dmirror_read() and dmirror_write()\nretry loops after dmirror_do_read…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nlib/test_hmm: fail dmirror_fault() when the mirrored mm is gone\n\ndmirror_fault() is called from the dmirror_read() and dmirror_write()\nretry loops after dmirror_do_read…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= b2ef9f5a5cb37643ca5def3516c546457074b882 < 50606ced303782f8715e2d0b98ca374ea498fa29","Linux >= b2ef9f5a5cb37643ca5def3516c546457074b882 < 541a67f21ab807c8dbc0ea88d5a2eb73b2618090","Linux >= b2ef9f5a5cb37643ca5def3516c546457074b882 < d8e64ffab01e032ae29159d27230ace8cf8bdc80","Linux >= b2ef9f5a5cb37643ca5def3516c546457074b882 < 2636569ea7c19d9a40db4a1e8d0a027bdacf1569","Linux >= b2ef9f5a5cb37643ca5def3516c546457074b882 < 701347e31aa607f3782403151a3125729d685275","Linux >= b2ef9f5a5cb37643ca5def3516c546457074b882 < af7a6d6ec36a16a583ba2e4e9984c3cf1fe34655","Linux >= b2ef9f5a5cb37643ca5def3516c546457074b882 < a2074f86fc9653831e4fb7b711bb715db330f182","Linux >= b2ef9f5a5cb37643ca5def3516c546457074b882 < 6a8024511ddf4877435c34fb3d6028aa8e590649","Linux 5.8"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:38.653","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90391","references":[{"url":"https://git.kernel.org/stable/c/2636569ea7c19d9a40db4a1e8d0a027bdacf1569","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50606ced303782f8715e2d0b98ca374ea498fa29","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/541a67f21ab807c8dbc0ea88d5a2eb73b2618090","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a8024511ddf4877435c34fb3d6028aa8e590649","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/701347e31aa607f3782403151a3125729d685275","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2074f86fc9653831e4fb7b711bb715db330f182","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af7a6d6ec36a16a583ba2e4e9984c3cf1fe34655","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8e64ffab01e032ae29159d27230ace8cf8bdc80","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.803Z","epss":0.0021,"epssPercentile":0.1154,"slug":"CVE-2026-90391","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlib/test_hmm: fail dmirror_fault() when the mirrored mm is gone\n\ndmirror_fault() is called from the dmirror_read() and dmirror_write()\nretry loops after dmirror_do_read() or dmirror_do_write() finds a missing\ndevice page table entry.\n\nIf the mirrored mm has already exited, mmget_not_zero() fails.  The\ncurrent code returns 0 in that case, which tells the caller that faulting\nsucceeded even though no page was faulted and no device page table entry\nwas installed.  The caller then retries the same address, hits -ENOENT\nagain, and can loop forever without making progress.\n\nReturn -EFAULT instead, so the ioctl fails when the mirrored mm is no\nlonger faultable.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}