Improper locking in Linux kernel - CVE-2026-89857
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause duplicated or dropped commands.
The vulnerability exists due to improper locking in the qla_nvme_ls_reject_iocb() request-ring handling when processing NVMe-FC link-service error responses and purex packets. A remote attacker can send NVMe-FC link-service traffic that triggers concurrent request-ring operations to cause duplicated or dropped commands.
Affected software
How to mitigate CVE-2026-89857
External References
- https://git.kernel.org/stable/c/11834e5773e20fd3742d7eb900876e66b9e7d029
- https://git.kernel.org/stable/c/7eb618877503edbf17aa65e357a81bda1fc8f163
- https://git.kernel.org/stable/c/b02ff132017b28222187ebcf95ce7f4cb576cd36
- https://git.kernel.org/stable/c/b3a362466db6b8ec47cc537ac641ac197fa69b5d
- https://git.kernel.org/stable/c/f743488e4a203049f27ec5d8cd0caccc483af01e