CVE-2026-89862
CVE CVE-2026-89862EUVD EUVD-2026-80462Published 2026-09-16T10:31:33.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix BSG job leak on validate flash image error path qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally, telling the FC BSG transport (fc_bsg_host_dispatch()) that the driver owns and will complete the request. But bsg_job_done() is guarded by "if (!rval)", so on the error path (rval == -EINVAL) neither the driver nor the transport completes the job. The request dangles until it times out, leaking block layer resources. Commit c2c68225b145 ("scsi: qla2xxx: Fix bsg_done() causing double free") added the "if (!rval)" guard to a batch of BSG handlers. That is correct for handlers that also return the error code (the transport then completes the job once via fail_host_msg), but this function returns QLA_SUCCESS unconditionally, so the guard turned a correct single completion into a leak. Always call bsg_job_done(): bsg_reply->result is DID_OK and the error is reported in vendor_rsp[0], and since the function returns 0 the transport will not complete the job a second time.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 871f6236da96c4a9712b8a29d7f555f767a47e95; 6.1.164 <6.2; 708003e1bc857dd014d4c44278d7d77c26f91b1c; c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0 <0fb52cc632464b0cd07f970341330466d772efe1; 74e7458537cd9349cf019862e51491f670871707; c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0 <e25241f9fa01fb0c088381a156d84a725b71c1ef; 7.0; 31f33b856d2324d86bcaef295f4d210477a1c018; patch: 0; 5.15.201 <5.16; f2bbb4db0e4a4fbd5e649c0b5d8733f61da24720; 5.10.251 <5.11; patch: 7.2.5; 6.12.74 <6.13; 27ac9679c43a09e54e2d9aae9980ada045b428e0; 6.18.13 <6.19; patch: 7.3-rc1; 6.6.127 <6.7; 6.19.3 <6.20; 057a5bdc481e58ab853117254867ffb22caf9f6e
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.