CVE-2026-72085
CVE CVE-2026-72085EUVD EUVD-2026-59043Published 2026-08-15T05:52:33.000ZLast changed 2026-08-17T05:40:07.000ZCVSS 9.3
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it scsiback_get_pend_req() obtains a command tag and returns a vscsibk_pend whose embedded se_cmd has only been memset to 0, so its cmd_kref is 0; the se_cmd is initialised (kref_init() via target_init_cmd()) only later, in scsiback_cmd_exec(), on the successful VSCSIIF_ACT_SCSI_CDB path. The two error paths in scsiback_do_cmd_fn() taken before the command is submitted -- a failed scsiback_gnttab_data_map() and an unknown ring_req.act -- call transport_generic_free_cmd(&pending_req->se_cmd, 0), which kref_put()s a refcount of 0. That underflows it ("refcount_t: underflow; use-after-free") and, as the release function is not run, leaks the command tag. Impact: a pvSCSI guest can leak every command tag of a LUN's session, stopping the LUN, by submitting requests with a bad grant reference or an unknown request type; under panic_on_warn the refcount underflow panics the host. Add a helper that just returns the tag with target_free_tag() and sends the error response. It frees the tag while the v2p reference still pins the session, and snapshots the response fields beforehand because freeing the tag can let another ring reuse the pending_req slot.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.2; 2dbcdf33dbf61f44b29adb52338282c3d7840d0e <f1516c56ac540da1769f264c3cfefe4499548a5d; patch: 0; 2dbcdf33dbf61f44b29adb52338282c3d7840d0e <fcd64d4d97af5d9736f31040f8ed8cd4c17e4c45; patch: 5.15.212; 2dbcdf33dbf61f44b29adb52338282c3d7840d0e <1e97c404e44991fb087c38ccd7414f2d326f9b74; 4.6; patch: 6.12.97; 2dbcdf33dbf61f44b29adb52338282c3d7840d0e <fa588f28401102652068c4cc75e135507f4b5106; patch: 6.1.178; patch: 7.1.5; 2dbcdf33dbf61f44b29adb52338282c3d7840d0e <9c0f6894982b1f13bda220707497b25ac9c95bdb; 2dbcdf33dbf61f44b29adb52338282c3d7840d0e <a13b789497a7fdd27d4d63f5c69d23db706ef0fe; 2dbcdf33dbf61f44b29adb52338282c3d7840d0e <ca978f8a93d4d36841839bf2847d29b88c2591d6; patch: 6.18.40; patch: 6.6.145
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.