CVE-2026-89853

Summary

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump

qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the buffer) under hardware_lock and never take fce_mutex. A debugfs FCE disable could therefore free the DMA buffer between a dump's NULL check and its copy, resulting in a use-after-free.

Unpublish ha->fce under hardware_lock, then release the lock and free the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either completes its check and copy with the buffer still valid, or observes ha->fce == NULL and skips it.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux3a5a789494875376d1f8063ec5ecc6beafda2ce1 < 423487f03e325b8665d20a2a3171fe012b1a4fa9affected
LinuxLinux73d3d3c66f108bc47922490f8500842530139975 < 7bd308cd893e8cce023d03a40a2f0adccaff0175affected
LinuxLinux57c029cab0d908942e3ed9ff9fd0361144d01944 < edc464a4fc96e2720d166e7cc7e7a6827b086760affected
LinuxLinux217230bc8796a922d5b15a9a94ec4414b2d2b3e3 < 6003e79148eca73d7cafb076f5be47e234d543d0affected
LinuxLinux2cf3c3fe9a11aa168e80c966494c58548b9aed5d < ef9b89f6c92274c3670403fd06130ca25f685050affected
LinuxLinux841df27d619ee1f5ca6473e15227b39d6136562d < 8e7a26931b6111583cfeaf49c068f26524dc3af2affected
LinuxLinux841df27d619ee1f5ca6473e15227b39d6136562d < 41ef7edde27ac87d55ffc703da44e78aa8c2e896affected
LinuxLinux841df27d619ee1f5ca6473e15227b39d6136562d < 53298efcbbb0f0438366d45cb7ed7e6d93dd5531affected
LinuxLinuxa89872a61b914378591f16e428dd221c5e2059b2affected
LinuxLinux5.10.235 < 5.10.270affected
LinuxLinux5.15.179 < 5.15.221affected
LinuxLinux6.1.129 < 6.1.188affected
LinuxLinux6.6.78 < 6.6.157affected
LinuxLinux6.12.14 < 6.12.110affected
LinuxLinux6.13.3 < 6.14affected
LinuxLinux6.14affected
LinuxLinux0 < 6.14unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References