{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "dbec4c9040edc15442c3ebdb65408aa9d3b82c24"
            },
            {
              "fixed": "3361709fb6f6568b157c6f24ed21a4a5d86d73db"
            },
            {
              "fixed": "240b582b6372bebb1245d911add9954b7dd6c02d"
            },
            {
              "fixed": "a61181f9ee30a98d2350c1bff32954a7521f9a23"
            },
            {
              "fixed": "afedf35df054bd713e9e13771aa0a056932c5c67"
            },
            {
              "fixed": "bc3398db3b64729b4a7907af317daad04795ad40"
            },
            {
              "fixed": "2dbdd025b228110ccbfbab95fe16e098313a14af"
            },
            {
              "fixed": "e2cd23443d3616ea0876f27762b17e2ec67d896c"
            },
            {
              "fixed": "b9f679dfe629004b593f018df33b330d799bcee4"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.16.0"
            },
            {
              "fixed": "5.10.270"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.221"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.188"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.157"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.110"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.52"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90202.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers\n\n_base_release_memory_pools() unconditionally frees every\nioc-\u003epcie_sg_lookup[] entry, including ones the setup loop never\nallocated after a partial failure, causing a \"bad dma\" warning on debug\nkernels or a NULL pointer dereference otherwise.",
  "id": "CVE-2026-90202",
  "modified": "2026-09-19T03:30:33.301500774Z",
  "published": "2026-09-17T16:07:19.514Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/240b582b6372bebb1245d911add9954b7dd6c02d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/2dbdd025b228110ccbfbab95fe16e098313a14af"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/3361709fb6f6568b157c6f24ed21a4a5d86d73db"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a61181f9ee30a98d2350c1bff32954a7521f9a23"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/afedf35df054bd713e9e13771aa0a056932c5c67"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b9f679dfe629004b593f018df33b330d799bcee4"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/bc3398db3b64729b4a7907af317daad04795ad40"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e2cd23443d3616ea0876f27762b17e2ec67d896c"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90202.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90202"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers"
}