CVE-2026-89514

Summary

In the Linux kernel, the following vulnerability has been resolved:

scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock

fnic_fcoe_process_vlan_resp() allocates a VLAN descriptor with kzalloc_obj() (default GFP_KERNEL) while holding vlans_lock via spin_lock_irqsave(). GFP_KERNEL may sleep, which is not allowed in this atomic context and can trigger a sleeping-from-invalid-context warning or deadlock.

Pass GFP_ATOMIC so the allocation is safe under the IRQ-safe spinlock.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux098585aa8acab3fcd46ce908af84ef168f5ccab6 < c4ade059aaeb51fdb3f4ae71e1ea3e2019b85178affected
LinuxLinux098585aa8acab3fcd46ce908af84ef168f5ccab6 < d86f65aed01408613607f8fc31493f07554788f2affected
LinuxLinux098585aa8acab3fcd46ce908af84ef168f5ccab6 < 9639c6324524ea3f934908bd51f02430000954abaffected
LinuxLinux6.14affected
LinuxLinux0 < 6.14unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References