NULL pointer dereference in Linux kernel - CVE-2026-89863
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in qla_chk_edif_rx_sa_delete_pending() when processing a firmware status completion for a command that has already been returned or aborted. A remote attacker can trigger processing of such a status completion to cause a denial of service.
The kernel crash occurs in interrupt context.
Affected software
How to mitigate CVE-2026-89863
External References
- https://git.kernel.org/stable/c/2191b0034a2f1307d421782e6eceddf8eec9e7f6
- https://git.kernel.org/stable/c/75fd6d041c4a325ae37f4683e6678d3015988bb0
- https://git.kernel.org/stable/c/94bfb61478bcb207d27f8cd24fd231421059519f
- https://git.kernel.org/stable/c/96eb8a3fc9f7fe7ba32679fcf1d2fd7d251e7a8b
- https://git.kernel.org/stable/c/c20ee380ca59c5a8646750c4849969a815924e2e
- https://git.kernel.org/stable/c/de0c8ef3b900c5e971c82ef38c6f5c22c5f3d8c1
- https://git.kernel.org/stable/c/e479e9b148456905d12711411484b94083c8ff58