CVE-2026-89853
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the buffer) under hardware_lock and never take fce_mutex. A debugfs FCE disable could therefore free the DMA buffer between a dump's NULL check and its copy, resulting in a use-after-free.
Unpublish ha->fce under hardware_lock, then release the lock and free the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either completes its check and copy with the buffer still valid, or observes ha->fce == NULL and skips it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 3a5a789494875376d1f8063ec5ecc6beafda2ce1 < 423487f03e325b8665d20a2a3171fe012b1a4fa9 | affected |
| Linux | Linux | 73d3d3c66f108bc47922490f8500842530139975 < 7bd308cd893e8cce023d03a40a2f0adccaff0175 | affected |
| Linux | Linux | 57c029cab0d908942e3ed9ff9fd0361144d01944 < edc464a4fc96e2720d166e7cc7e7a6827b086760 | affected |
| Linux | Linux | 217230bc8796a922d5b15a9a94ec4414b2d2b3e3 < 6003e79148eca73d7cafb076f5be47e234d543d0 | affected |
| Linux | Linux | 2cf3c3fe9a11aa168e80c966494c58548b9aed5d < ef9b89f6c92274c3670403fd06130ca25f685050 | affected |
| Linux | Linux | 841df27d619ee1f5ca6473e15227b39d6136562d < 8e7a26931b6111583cfeaf49c068f26524dc3af2 | affected |
| Linux | Linux | 841df27d619ee1f5ca6473e15227b39d6136562d < 41ef7edde27ac87d55ffc703da44e78aa8c2e896 | affected |
| Linux | Linux | 841df27d619ee1f5ca6473e15227b39d6136562d < 53298efcbbb0f0438366d45cb7ed7e6d93dd5531 | affected |
| Linux | Linux | a89872a61b914378591f16e428dd221c5e2059b2 | affected |
| Linux | Linux | 5.10.235 < 5.10.270 | affected |
| Linux | Linux | 5.15.179 < 5.15.221 | affected |
| Linux | Linux | 6.1.129 < 6.1.188 | affected |
| Linux | Linux | 6.6.78 < 6.6.157 | affected |
| Linux | Linux | 6.12.14 < 6.12.110 | affected |
| Linux | Linux | 6.13.3 < 6.14 | affected |
| Linux | Linux | 6.14 | affected |
| Linux | Linux | 0 < 6.14 | unaffected |
| Linux | Linux | 5.10.270 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.221 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.188 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.157 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/423487f03e325b8665d20a2a3171fe012b1a4fa9
- https://git.kernel.org/stable/c/7bd308cd893e8cce023d03a40a2f0adccaff0175
- https://git.kernel.org/stable/c/edc464a4fc96e2720d166e7cc7e7a6827b086760
- https://git.kernel.org/stable/c/6003e79148eca73d7cafb076f5be47e234d543d0
- https://git.kernel.org/stable/c/ef9b89f6c92274c3670403fd06130ca25f685050
- https://git.kernel.org/stable/c/8e7a26931b6111583cfeaf49c068f26524dc3af2
- https://git.kernel.org/stable/c/41ef7edde27ac87d55ffc703da44e78aa8c2e896
- https://git.kernel.org/stable/c/53298efcbbb0f0438366d45cb7ed7e6d93dd5531
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.