Use-after-free in Linux kernel - CVE-2026-89848
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to use-after-free in the qla2xxx request queue handling when processing response-queue interrupts during queue teardown. A remote attacker can trigger a late response completion during queue teardown to compromise confidentiality, integrity, and availability.
Affected software
How to mitigate CVE-2026-89848
External References
- https://git.kernel.org/stable/c/10e9f05f7fd0a103886a867ec8afe621fe4b906a
- https://git.kernel.org/stable/c/1486cc18be3e2b4c2a730f4a1b0448d009381b3d
- https://git.kernel.org/stable/c/157ca7d1af45f87aa14a286754f19c3f72386988
- https://git.kernel.org/stable/c/505753ec2594c6af09a601f0dd60be7d840c1d2d
- https://git.kernel.org/stable/c/7ac5be2a8609679fc6bbfea881360444a5ce8202