{"id":"CVE-2026-90216","summary":"ubi: Fix rollback for explicit UBI device numbers","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nubi: Fix rollback for explicit UBI device numbers\n\nubi_init_attach() rolls back module initialization failures by scanning\nubi_devices[0..i-1], where i is the mtd= parameter index. That assumes\nthe parameter index matches the UBI device number.\n\nThat assumption is not true when mtd= specifies an explicit ubi_num. A\nsuccessfully attached device can be stored at a higher ubi_devices[]\nslot, and a later failure can miss it during rollback.\n\nScan the full ubi_devices[] array and detach by the actual array index,\nmatching the way UBI devices are stored.","modified":"2026-09-18T03:48:36.384305937Z","published":"2026-09-17T16:07:28.730Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90216.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4417ab6ecad01cf2d01045ef8104c95a66b0e893"},{"type":"WEB","url":"https://git.kernel.org/stable/c/552e565ed8846e7db143e4a6bdf3f5677453c686"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5b0a6b554e12a97f9771a9a9f4ea1f5457373c73"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6b92e66ec6dd8019e8efb2a568ef7c967c5a18c5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/83c978921688af40dcab6db74882d1ff9b0b765c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/87b3da4acb860605643ebee312178f13b20744cf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9754f049d5f1945d4c691d1f52824eb8daf8f9be"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e3f7e58189bc222971ddc860f1716f37e51ba996"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90216.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90216"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"83ff59a066637a6c28844bbf43009459408240f4"},{"fixed":"83c978921688af40dcab6db74882d1ff9b0b765c"},{"fixed":"6b92e66ec6dd8019e8efb2a568ef7c967c5a18c5"},{"fixed":"4417ab6ecad01cf2d01045ef8104c95a66b0e893"},{"fixed":"552e565ed8846e7db143e4a6bdf3f5677453c686"},{"fixed":"9754f049d5f1945d4c691d1f52824eb8daf8f9be"},{"fixed":"e3f7e58189bc222971ddc860f1716f37e51ba996"},{"fixed":"87b3da4acb860605643ebee312178f13b20744cf"},{"fixed":"5b0a6b554e12a97f9771a9a9f4ea1f5457373c73"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90216.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.11.0"},{"fixed":"5.10.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90216.json"}}],"schema_version":"1.9.0"}