CVE-2026-89857
CVE CVE-2026-89857EUVD EUVD-2026-80457Veröffentlicht 2026-09-16T10:31:30.000ZZuletzt geändert 2026-09-16T14:39:21.000ZCVSS 9.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject qla_nvme_ls_reject_iocb() allocates from and advances the request ring through __qla2x00_alloc_iocbs() (which assumes the hardware_lock is held) and qla2x00_start_iocbs() (which advances the ring and rings the request-in doorbell), but takes no lock itself. Two of its callers invoke it without the producer lock held: - qla_nvme_xmt_ls_rsp(), the NVMe-FC .xmt_ls_rsp transport callback, on its error path, and - qla2xxx_process_purls_pkt(), run from the purex work/DPC context. Both use ha->base_qpair, whose qp_lock_ptr is hardware_lock, so they can run concurrently with normal I/O submission on the base ring and corrupt the ring producer state, leading to duplicated or dropped commands. The third caller, qla2xxx_process_purls_iocb(), runs inside qla24xx_process_response_queue() with the qpair lock already held and is safe; that is also why the lock cannot be taken inside the helper itself (it would recursively re-acquire hardware_lock on the response path). Take qp_lock_ptr around the two unlocked callers and document the helper as caller-locked. Both run in process context, so spin_lock_irqsave() is used and nothing in the locked region sleeps.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 875386b98857822b77ac7f95bdf367b70af5b78c <11834e5773e20fd3742d7eb900876e66b9e7d029; 875386b98857822b77ac7f95bdf367b70af5b78c <f743488e4a203049f27ec5d8cd0caccc483af01e; patch: 6.6.157; 875386b98857822b77ac7f95bdf367b70af5b78c <b3a362466db6b8ec47cc537ac641ac197fa69b5d; patch: 7.3-rc1; patch: 6.12.110; 6.6; patch: 0; 875386b98857822b77ac7f95bdf367b70af5b78c <b02ff132017b28222187ebcf95ce7f4cb576cd36; patch: 7.2.5; patch: 6.18.51; 875386b98857822b77ac7f95bdf367b70af5b78c <7eb618877503edbf17aa65e357a81bda1fc8f163
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.