CVE-2026-89861
CVE CVE-2026-89861EUVD EUVD-2026-80461Published 2026-09-16T10:31:32.000ZLast changed 2026-09-16T14:39:24.000ZCVSS 8.1
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() In the format 1 path, the virtual port is located on ha->vp_list while holding vport_slock, but the lock is dropped before vp is used: qla_update_host_map() is called and VP_IDX_ACQUIRED/REGISTER_FC4_NEEDED/ REGISTER_FDMI_NEEDED are set on vp. No reference is taken across that window, so a concurrent qla24xx_deallocate_vp_id() can tear the vport down and free it, leading to a use-after-free. Take a vport reference (vref_count) under vport_slock when the matching vp is found, and drop it after the last use of vp. qla24xx_deallocate_vp_id() waits for vref_count to reach zero before unlinking and freeing the vport, so the pointer stays valid. This matches the reference idiom already used by the other ha->vp_list traversals.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 2c3dfe3f6ad8daff5acdb01713e4f2b116e78136 <f8d2eb510c063a8ca79a5dc766a4303d3925fe83; patch: 6.18.51; 2c3dfe3f6ad8daff5acdb01713e4f2b116e78136 <f6b3bcc7cb2f4c37464958b9fd97dc7f185ea297; patch: 5.15.221; 2c3dfe3f6ad8daff5acdb01713e4f2b116e78136 <47272152a13d202d98496208f9bf382c1cf4d4fb; 2c3dfe3f6ad8daff5acdb01713e4f2b116e78136 <4b7f0a95bfeb1d3673da4c29bbe9872a61bc1a69; 2c3dfe3f6ad8daff5acdb01713e4f2b116e78136 <d556f899964d184e6cb788f3fa9dcddcafe1ab2d; 2c3dfe3f6ad8daff5acdb01713e4f2b116e78136 <d09ef32af1e05d79f29b460521a20bc4e6fd2ecf; patch: 0; patch: 6.1.188; patch: 6.6.157; 2c3dfe3f6ad8daff5acdb01713e4f2b116e78136 <267533b28ddf2c9223d30ad7e6960fa9e936428e; patch: 7.3-rc1; 2.6.23; patch: 5.10.270; patch: 6.12.110; 2c3dfe3f6ad8daff5acdb01713e4f2b116e78136 <793cedee296fd819bfadc2a7ec4d52faf9c09a0a; patch: 7.2.5
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.