CVE-2026-64103
CVE CVE-2026-64103EUVD EUVD-2026-45788Veröffentlicht 2026-07-19T15:40:07.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: scsi: isci: Fix use-after-free in device removal path The ISCI completion tasklet is initialized in isci_host_alloc() (drivers/scsi/isci/init.c:496) and scheduled from both MSI-X and legacy interrupt handlers (drivers/scsi/isci/host.c:223,613). isci_host_deinit() stops the controller and waits for stop completion, but it never kills completion_tasklet before teardown continues. A top-of-function tasklet_kill() is not sufficient here: interrupts are only disabled when isci_host_stop_complete() runs, so until wait_for_stop() returns the IRQ handlers can still requeue the tasklet. The tasklet callback also re-enables interrupts after draining completions, so killing the tasklet before the source is quiesced leaves the same race open. Once wait_for_stop() returns, no further IRQ-driven scheduling can occur. Kill completion_tasklet there so teardown cannot race a queued tasklet running on a dead ihost. On remove or unload, the stale callback can otherwise dereference ihost and touch ihost->smu_registers after the host lifetime ends. A UML + KASAN analogue reproduced the failure class both with no tasklet_kill() and with tasklet_kill() placed before source quiesce, and stayed clean once the kill happened after quiescing the scheduling source. This mirrors commit f6ab594672d4 ("scsi: aic94xx: fix use-after-free in device removal path"), but ISCI needs the kill after wait_for_stop().
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 6f231dda68080759f1aed3769896e94c73099f0f <1412995e10c74644b47f242aea6e4f3d4180e806; patch: 5.10.258; patch: 5.15.209; 6f231dda68080759f1aed3769896e94c73099f0f <ab2266601a875982f2d2033f41e070a6d5e615e2; 3.0; 6f231dda68080759f1aed3769896e94c73099f0f <b9ff8631006233ba246828ac70409d2cb2da38d3; patch: 0; 6f231dda68080759f1aed3769896e94c73099f0f <cb9e72c50e6c81a5903f27e0b397ce8525d7539b; patch: 6.12.92; 6f231dda68080759f1aed3769896e94c73099f0f <b52a8d52c3125ec9a93106ed816582368de34426; 6f231dda68080759f1aed3769896e94c73099f0f <6d40f2f103bb30f52f3dbadbe2c3fdf274a9763c; 6f231dda68080759f1aed3769896e94c73099f0f <309c6058622d080fe8c2fab87c30da82d834d989; patch: 6.6.142; patch: 7.0.11; patch: 6.1.175; patch: 7.1; 6f231dda68080759f1aed3769896e94c73099f0f <a83d3e4daba40d49324cec1c51ed261e1ea48cf1; patch: 6.18.34
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.