Use-after-free in Linux kernel - CVE-2026-89861
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to use-after-free in qla24xx_report_id_acquisition() in the qla2xxx SCSI driver when a virtual port is concurrently deallocated after it is found in the virtual port list. A remote attacker can trigger the race condition to compromise confidentiality, integrity, and availability.
Affected software
How to mitigate CVE-2026-89861
External References
- https://git.kernel.org/stable/c/267533b28ddf2c9223d30ad7e6960fa9e936428e
- https://git.kernel.org/stable/c/47272152a13d202d98496208f9bf382c1cf4d4fb
- https://git.kernel.org/stable/c/4b7f0a95bfeb1d3673da4c29bbe9872a61bc1a69
- https://git.kernel.org/stable/c/793cedee296fd819bfadc2a7ec4d52faf9c09a0a
- https://git.kernel.org/stable/c/d09ef32af1e05d79f29b460521a20bc4e6fd2ecf
- https://git.kernel.org/stable/c/d556f899964d184e6cb788f3fa9dcddcafe1ab2d
- https://git.kernel.org/stable/c/f6b3bcc7cb2f4c37464958b9fd97dc7f185ea297
- https://git.kernel.org/stable/c/f8d2eb510c063a8ca79a5dc766a4303d3925fe83