Race condition in Linux kernel - CVE-2026-80653
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper synchronization in the hisi_sas v3 hardware SCSI device link handling when executing a remote PHY link reset concurrently with driver removal. A local user can trigger concurrent link reset and device removal operations to cause a kernel warning and destabilize the system.
The issue occurs during SAS PHY revalidation and device cleanup in the hisi_sas driver.