CVE-2026-89853
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-89853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-16
Last updated on: 2026-09-16
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
qla2x00_free_fce_trace() freed and cleared ha->fce while holding only
fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and
qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the
buffer) under hardware_lock and never take fce_mutex. A debugfs FCE
disable could therefore free the DMA buffer between a dump's NULL check
and its copy, resulting in a use-after-free.
Unpublish ha->fce under hardware_lock, then release the lock and free
the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either
completes its check and copy with the buffer still valid, or observes
ha->fce == NULL and skips it.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 3a5a789494875376d1f8063ec5ecc6beafda2ce1 |
| Linux | Linux | 73d3d3c66f108bc47922490f8500842530139975 |
| Linux | Linux | 57c029cab0d908942e3ed9ff9fd0361144d01944 |
| Linux | Linux | 217230bc8796a922d5b15a9a94ec4414b2d2b3e3 |
| Linux | Linux | 2cf3c3fe9a11aa168e80c966494c58548b9aed5d |
| Linux | Linux | 841df27d619ee1f5ca6473e15227b39d6136562d |
| Linux | Linux | 841df27d619ee1f5ca6473e15227b39d6136562d |
| Linux | Linux | 841df27d619ee1f5ca6473e15227b39d6136562d |
| Linux | Linux | a89872a61b914378591f16e428dd221c5e2059b2 |
| Linux | Linux | 5.10.235 |
| Linux | Linux | 5.15.179 |
| Linux | Linux | 6.1.129 |
| Linux | Linux | 6.6.78 |
| Linux | Linux | 6.12.14 |
| Linux | Linux | 6.13.3 |
| Linux | Linux | 6.14 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |