CVE-2026-90009 | Linux Kernel up to 7.2.4/7.3-rc1 bsg scsi_bsg_uring_cmd toctou
A vulnerability classified as very critical has been found in Linux Kernel up to 7.2.4/7.3-rc1. The affected element is the function scsi_bsg_uring_cmd of the component bsg. Performing a manipulation results in time-of-check time-of-use.
This vulnerability was named CVE-2026-90009. The attack needs to be approached locally. There is no available exploit.
It is recommended to upgrade the affected component.