CVE-2026-89853
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-89853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the buffer) under hardware_lock and never take fce_mutex. A debugfs FCE disable could therefore free the DMA buffer between a dump's NULL check and its copy, resulting in a use-after-free. Unpublish ha->fce under hardware_lock, then release the lock and free the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either completes its check and copy with the buffer still valid, or observes ha->fce == NULL and skips it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
Linux Linux 3a5a789494875376d1f8063ec5ecc6beafda2ce1
Linux Linux 73d3d3c66f108bc47922490f8500842530139975
Linux Linux 57c029cab0d908942e3ed9ff9fd0361144d01944
Linux Linux 217230bc8796a922d5b15a9a94ec4414b2d2b3e3
Linux Linux 2cf3c3fe9a11aa168e80c966494c58548b9aed5d
Linux Linux 841df27d619ee1f5ca6473e15227b39d6136562d
Linux Linux 841df27d619ee1f5ca6473e15227b39d6136562d
Linux Linux 841df27d619ee1f5ca6473e15227b39d6136562d
Linux Linux a89872a61b914378591f16e428dd221c5e2059b2
Linux Linux 5.10.235
Linux Linux 5.15.179
Linux Linux 6.1.129
Linux Linux 6.6.78
Linux Linux 6.12.14
Linux Linux 6.13.3
Linux Linux 6.14

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart