CVE-2026-90421EPSS p8.7%
CVE-2026-90421CVE-2026-90421
Description
In the Linux kernel, the following vulnerability has been resolved:
PCI: Fix UAF when probe runs concurrent to dyn ID removal
Dynamic IDs are only guaranteed to be valid when dynids.lock is held,
as remove_id_store() can free the node. Thus, make a copy in
pci_match_device(). Also, clarify that the id parameter is only valid
during probe.
Scoring
| EPSS | 0.20% probability of exploitation · percentile 8.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-17 |