UNKNOWN NVD
CVE-2026-90310
In the Linux kernel, the following vulnerability has been resolved: xen/xenbus: check otherend_id only after it has been initialized When device just got init
In the Linux kernel, the following vulnerability has been resolved:
xen/xenbus: check otherend_id only after it has been initialized
When device just got initialized (for example on module load), the
otherend_id field is initialized only after
xenbus_read_otherend_details() gets called. If xenstore watch triggers
xenbus_dev_changed() before that, it might consider still zeroed
otherend_id field (not matching actual xenstore content) as a sign of
device state reset. It can happen because xenstore watch are handled in
another thread (xenwatch), which can run in parallel to the initial
device probe running at module load. In that case, it would call
device_unregister(), which would deadlock against device probe from
module init.
Fix this by considering dev->otherend_id change only after dev->otherend
is set (which happen after otherend_id is initialized).
References
- https://git.kernel.org/stable/c/36fb592af353c55832e2cafe3fcfc3291be05f19
- https://git.kernel.org/stable/c/c76cbf348c7df077f93fa99a1225a527ce64cfa1
This unknown severity vulnerability was published on 2026-09-17 via NVD.
vulnfeed aggregates 13500 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.