CVE-2026-63889
Last modified
CVE-2026-63889 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in the generic FC transport. This is not a local userspace or IP network path; the attacker must be able to inject fabric traffic, for example as a compromised switch or fabric controller, or as a same-zone N_Port on a fabric that permits source spoofing. The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop counter against the 32-bit on-wire pname_count field, and did not bound pname_count by the descriptor body already validated by the TLV walker. A pname_count of 256 therefore wraps the counter and keeps the loop condition true indefinitely. Factor the shared pname_list[] walk into one helper, widen the counter to u32, and clamp pname_count against the entries that fit in the descriptor body before iterating.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in the generic FC transport. This is not a local userspace or IP network path; the attacker must be able to inject fabric traffic, for example as a compromised switch or fabric controller, or as a same-zone N_Port on a fabric that permits source spoofing. The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop counter against the 32-bit on-wire pname_count field, and did not bound pname_count by the descriptor body already validated by the TLV walker. A pname_count of 256 therefore wraps the counter and keeps the loop condition true indefinitely. Factor the shared pname_list[] walk into one helper, widen the counter to u32, and clamp pname_count against the entries that fit in the descriptor body before iterating.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3, < 07776b7779c9426982c1ad74aad91bd531593790; >= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3, < 29f126f09e34a425b376b3646c89aa7cc18b142c; >= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3, < 163bd704d7515c3df6c2e03bcba93d1db79edbff; >= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3, < ee57b89e5da9fffbe0d26647e4ff0750dacb9943; >= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3, < 35461d23744175a78b6280293892cca357c22793; >= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3, < bdff76dff6ec23d6fe35812fa33e5c4ce2cdb770; >= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3, < a9a39233ec1fc9f97ea1340a4d09bb7ec2be5153 |
| Linux | Linux | 5.11 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-63889?
How severe is CVE-2026-63889?
How do I fix CVE-2026-63889?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63883In the Linux kernel, the following vulnerability has been re…7.3
- CVE-2026-63884In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-63885In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-63886In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-63887In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-63888In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-6389IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Tu…7.8
- CVE-2026-63890In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63891In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63892In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63893In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-63894In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-63889?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
