Junglewise Threat Intelligence

CVE-2026-90180: Linux kernel mtip32xx race condition in ioctl and device removal

CVE-2026-90180 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's mtip32xx driver (used for Micron RealSSD PCIe flash storage devices) contains a race condition between ioctl operations and device removal. When a device is being removed from the system, in-flight ioctl calls can dereference freed memory, potentially causing a crash or system instability. This could affect servers or storage systems using these flash devices.

Technical details

The vulnerability is a use-after-free race condition in the mtip32xx block driver's ioctl handlers. The ioctl code path tested the REMOVE_PENDING flag before acquiring synchronization, but device removal could set that bit and free the dd->port structure immediately after the check but before the ioctl handler finished, leading to a dereference of freed memory. The fix serializes ioctl operations (both native and compat ioctls) with device removal by introducing a mutex that is held from the start of removal through teardown of the port structure. Attack vector requires local access with an ability to trigger ioctls on an already-open block device while device removal is in progress.

Affected products

  • Linux Linux kernel Multiple versions (fix applies to mtip32xx driver across stable branches 4.x, 5.x, 6.x, 7.x)

Timeline

  • 2026-09-17: disclosed: CVE-2026-90180 published

References

Related threats