CVE-2026-89853

Unknown

Last modified

CVE-2026-89853 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the buffer) under hardware_lock and never take fce_mutex.

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the buffer) under hardware_lock and never take fce_mutex. A debugfs FCE disable could therefore free the DMA buffer between a dump's NULL check and its copy, resulting in a use-after-free. Unpublish ha->fce under hardware_lock, then release the lock and free the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either completes its check and copy with the buffer still valid, or observes ha->fce == NULL and skips it.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 3a5a789494875376d1f8063ec5ecc6beafda2ce1, < 423487f03e325b8665d20a2a3171fe012b1a4fa9; >= 73d3d3c66f108bc47922490f8500842530139975, < 7bd308cd893e8cce023d03a40a2f0adccaff0175; >= 57c029cab0d908942e3ed9ff9fd0361144d01944, < edc464a4fc96e2720d166e7cc7e7a6827b086760; >= 217230bc8796a922d5b15a9a94ec4414b2d2b3e3, < 6003e79148eca73d7cafb076f5be47e234d543d0; >= 2cf3c3fe9a11aa168e80c966494c58548b9aed5d, < ef9b89f6c92274c3670403fd06130ca25f685050; >= 841df27d619ee1f5ca6473e15227b39d6136562d, < 8e7a26931b6111583cfeaf49c068f26524dc3af2; >= 841df27d619ee1f5ca6473e15227b39d6136562d, < 41ef7edde27ac87d55ffc703da44e78aa8c2e896; >= 841df27d619ee1f5ca6473e15227b39d6136562d, < 53298efcbbb0f0438366d45cb7ed7e6d93dd5531; a89872a61b914378591f16e428dd221c5e2059b2; >= 5.10.235, < 5.10.270; >= 5.15.179, < 5.15.221; >= 6.1.129, < 6.1.188; >= 6.6.78, < 6.6.157; >= 6.12.14, < 6.12.110; >= 6.13.3, < 6.14
LinuxLinux6.14

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-89853?
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the buffer) under hardware_lock and never take fce_mutex. A debugfs FCE disable could therefore free the DMA buffer between a dump's NULL check and its copy, resulting in a use-after-free. Unpublish ha->fce under hardware_lock, then release the lock and free the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either completes its check and copy with the buffer still valid, or observes ha->fce == NULL and skips it.
How severe is CVE-2026-89853?
Severity scoring for CVE-2026-89853 is pending analysis.
How do I fix CVE-2026-89853?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-89853?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST