Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90268NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

scsi: sd: Fix error handling in sd_probe() after large pool creation failure

After device_add(&sdkp->disk_dev) succeeds, sd_large_pool_create()
failure must unregister disk_dev and let scsi_disk_release() free
sdkp. Going through out_free_index kfree()s an already registered device
and leaks the sysfs entry.
Severity Level
HIGH(8.1)
Published Date
Sep 17, 2026
Last Modified
Sep 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.42%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 8.1 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 7179e626b76eb42f2529c6f6dd6ba88ea2445372 and < 748a14a0d41cfe3017251c11b314f85045414942
  • Linux Linux >= 7179e626b76eb42f2529c6f6dd6ba88ea2445372 and < e3cc6ea1a745e7f5d326f919a428b244fa119d8f
  • Linux Linux >= 7.1
Patched Versions
  • Linux Linux 748a14a0d41cfe3017251c11b314f85045414942
  • Linux Linux e3cc6ea1a745e7f5d326f919a428b244fa119d8f
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.