CVE-2026-90031Hinoki check available

Kernel warning via unsynchronized card-type probe

Published Sep 16, 2026 · Updated Sep 16, 2026

Race condition in the Linux ene_ub6250 USB-storage driver allows attackers to trigger concurrent use of an active URB during device probing. The card-type probe calls ene_get_card_type without holding the device mutex while delayed scan work can use the same current URB object. Reachability requires the driver to probe a compatible USB storage device; public evidence reports a kernel warning, not a crash or broader impact.

CVSS severityUnavailable
Unscored
EPSS probabilityUnavailable
No score available in this record
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkAvailable
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Race condition in the Linux ene_ub6250 USB-storage driver allows attackers to trigger concurrent use of an active URB during device probing. The card-type probe calls ene_get_card_type without holding the device mutex while delayed scan work can use the same current URB object. Reachability requires the driver to probe a compatible USB storage device; public evidence reports a kernel warning, not a crash or broader impact.

The record

CVE
CVE-2026-90031
Published
Sep 16, 2026
Updated
Sep 16, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
Unavailable
Attack vector
Unavailable
Privileges
Unavailable

Timeline

How it unfolded

  1. Sep 16, 2026CVE publishedPublication date reported by the CVE source.
  2. Sep 16, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <5.10.270
  2. Affected versionversion=0 <5.15.221
  3. Affected versionversion=0 <6.1.188
  4. Affected versionversion=0 <6.12.110
  5. Affected versionversion=0 <6.18.51
  6. Affected versionversion=0 <6.6.157
  7. Affected versionversion=0 <7.2.5
  8. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <1c67f2ba9c5f7c5ab3670671c0d51c6504bcaf74
  9. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <445fc368c6bc73eff0aeb3818cf5f355facfbb16
  10. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5082546702c32a2700894d2c0ace784e038ef6a3
  11. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <8936d95dd04d34db96d4d1e3899eee52605bbedc
  12. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9481bc04a8c351ed883a7f0e10939bbe9120ead7
  13. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <996c319b8bd5ada1f62daae0d331d0b23e0f2117
  14. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9c261a83131e241d67cb73ab578d0265bc19cfb5
  15. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9cd335f4f41e84d1ab88d80150ffee8dee9650d7

What conditions does exploitation require?

Attack vectorUnavailable in this record.
Required privilegesUnavailable in this record.

What is affected?

The Linux Kernel Organization · Linuxversion=0 <5.10.270; version=0 <5.15.221; version=0 <6.1.188; version=0 <6.12.110; version=0 <6.18.51; version=0 <6.6.157; version=0 <7.2.5; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <1c67f2ba9c5f7c5ab3670671c0d51c6504bcaf74; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <445fc368c6bc73eff0aeb3818cf5f355facfbb16; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5082546702c32a2700894d2c0ace784e038ef6a3; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <8936d95dd04d34db96d4d1e3899eee52605bbedc; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9481bc04a8c351ed883a7f0e10939bbe9120ead7; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <996c319b8bd5ada1f62daae0d331d0b23e0f2117; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9c261a83131e241d67cb73ab578d0265bc19cfb5; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9cd335f4f41e84d1ab88d80150ffee8dee9650d7

Published CVSS scores

No CVSS assessment is available in this record.

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
VectorUnavailable
PrivilegesUnavailable
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

No sourced classifications are available.

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo