{"id":"CVE-2026-90135","summary":"net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()\n\nsashiko is reporting that trying to read /sys/kernel/debug/ref_tracker/*\ncauses use-afer-free crash when either alloc_percpu() or dev_addr_init()\nin alloc_netdev_mqs() failed, for commit 4d92b95ff2f9 (\"net: add net device\nrefcount tracker infrastructure\") added ref_tracker_dir_exit() to only\nfree_netdev() path.","modified":"2026-09-19T03:47:28.585021315Z","published":"2026-09-17T16:06:34.543Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90135.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0b1c2af8a22c35cb099c735c2f63ea3ba757557d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2775bf36be7872834a7f8c0a0d9681a1a3e1cd4c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5fe03b5257095e2beef0bc79e1f068fbd09a24c7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/63ab05e8f9654aa100d366c0236399fda6ffaab1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90135.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90135"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4d92b95ff2f95f13df9bad0b5a25a9f60e72758d"},{"fixed":"2775bf36be7872834a7f8c0a0d9681a1a3e1cd4c"},{"fixed":"5fe03b5257095e2beef0bc79e1f068fbd09a24c7"},{"fixed":"63ab05e8f9654aa100d366c0236399fda6ffaab1"},{"fixed":"0b1c2af8a22c35cb099c735c2f63ea3ba757557d"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90135.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.17.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90135.json"}}],"schema_version":"1.9.0"}