CVE-2026-89850
CVE CVE-2026-89850EUVD EUVD-2026-80450Published 2026-09-16T10:31:24.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Don't query firmware state while chip is down qla2x00_fw_state_show() initializes rval to QLA_FUNCTION_FAILED and jumps to the out: label when the chip is down or EEH is busy. The out: block then re-issued qla2x00_get_firmware_state() because rval != QLA_SUCCESS, defeating the chip-down/EEH-busy guards and issuing a mailbox command (outside optrom_mutex) during ISP reset or PCI error recovery, which can hang the adapter. It also turned a normal in-lock mailbox failure into a second unsynchronized mailbox attempt. Make the out: fallback only mark the firmware state as unknown. The mailbox is now issued at most once, inside optrom_mutex, and only when the chip is up and not EEH-busy.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux b6faaaf796d7bfb00e32ca5c905d55cc43e89448 <22f44f77da496bc355479c08a0a9dbc9ad42ba42; patch: 6.18.51; b6faaaf796d7bfb00e32ca5c905d55cc43e89448 <cba780c01f72f8585ca81ad7304097f8b12ef339; patch: 5.10.270; b6faaaf796d7bfb00e32ca5c905d55cc43e89448 <a194684853dceaa1d6b7a9a02bc12f479232ad9b; patch: 6.12.110; patch: 6.6.157; patch: 0; b6faaaf796d7bfb00e32ca5c905d55cc43e89448 <b6a30baa29695fa0eaba4a3a04435a3c1a5cb63d; patch: 7.3-rc1; b6faaaf796d7bfb00e32ca5c905d55cc43e89448 <7bc2baed8a3d6a1e2a3f6b78d245f25d1e18a749; b6faaaf796d7bfb00e32ca5c905d55cc43e89448 <178d984e8875292582e4295cf559b2b11d3c9325; b6faaaf796d7bfb00e32ca5c905d55cc43e89448 <a6374b508893de15fee78583a95f5099d7812e85; 4.20; patch: 7.2.5; patch: 6.1.188; patch: 5.15.221; b6faaaf796d7bfb00e32ca5c905d55cc43e89448 <e0cebe20dcffbed9c078fe30e2d18cd5046d9eff
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.