CVE-2026-89853: falha em Linux
scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
Publicada em
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 0.2%
probabilidade de exploração
0.2%top 90% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
qla2x00_free_fce_trace() freed and cleared ha->fce while holding only
fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and
qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the
buffer) under hardware_lock and never take fce_mutex. A debugfs FCE
disable could therefore free the DMA buffer between a dump's NULL check
and its copy, resulting in a use-after-free.
Unpublish ha->fce under hardware_lock, then release the lock and free
the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either
completes its check and copy with the buffer still valid, or observes
ha->fce == NULL and skips it.
Produtos afetados
Linux · LinuxCVEs relacionadas — Linux
No mesmo produto, das mais perigosas para as menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referências
https://git.kernel.org/stable/c/41ef7edde27ac87d55ffc703da44e78aa8c2e896https://git.kernel.org/stable/c/423487f03e325b8665d20a2a3171fe012b1a4fa9https://git.kernel.org/stable/c/53298efcbbb0f0438366d45cb7ed7e6d93dd5531https://git.kernel.org/stable/c/6003e79148eca73d7cafb076f5be47e234d543d0https://git.kernel.org/stable/c/7bd308cd893e8cce023d03a40a2f0adccaff0175https://git.kernel.org/stable/c/8e7a26931b6111583cfeaf49c068f26524dc3af2https://git.kernel.org/stable/c/edc464a4fc96e2720d166e7cc7e7a6827b086760https://git.kernel.org/stable/c/ef9b89f6c92274c3670403fd06130ca25f685050