SB20260325168 - Incorrect Control Flow Scoping in Linux kernel scsi driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect Control Flow Scoping (CVE-ID: CVE-2026-23296)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper reference counting in the SCSI core subsystem when handling tagset reference counts during SCSI host teardown. A local user can trigger the removal of a SCSI host to cause a denial of service.
Repeated triggering of the issue may lead to system instability or hang due to unbounded reference accumulation.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1ac22c8eae81366101597d48360718dff9b9d980
- https://git.kernel.org/stable/c/7c01b680beaf4d3143866b062b8e770e8b237fb8
- https://git.kernel.org/stable/c/944a333c8e4d42256556c1d2ebb6d773a33e0dcd
- https://git.kernel.org/stable/c/9f5e4abed9248448aa1b45b12ab0bea4d329b56a
- https://git.kernel.org/stable/c/a03d96598d39fdf605d90731db3ef3b13fb8bdc8
- https://git.kernel.org/stable/c/ec5c17c687b189dbc09dfdec11b669caa40bc395