« Volver al listado

CVE-2026-74754

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: core: pair EH runtime PM get and put

shost->eh_noresume is currently consulted twice in one error handling iteration: once before scsi_autopm_get_host() and once again before scsi_autopm_put_host().

That is racy when a PM-triggered error path flips shost->eh_noresume while the SCSI EH thread is still running.

In that case one EH iteration can skip autoresume on entry and still drop a runtime PM reference on exit. That leaves an unmatched runtime PM put and can trigger a runtime PM usage count underflow.

Fix this by making eh_noresume a regular bool so it can be accessed with READ_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use that snapshot for both runtime PM get and put decisions.

Detalles técnicos trazas, registros y código del informe original
The problem flow looks like this:
PM path
  ufshcd_set_dev_pwr_mode()
    shost->eh_noresume = 1
    ufshcd_execute_start_stop  <-- trigger EH
    ...
    shost->eh_noresume = 0

EH path
  scsi_error_handler()
    if (!shost->eh_noresume)
      scsi_autopm_get_host()  <-- skipped
    ...
    if (!shost->eh_noresume)
       scsi_autopm_put_host()  <-- executed later

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74754",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ae0751ffc77e7f21629970fdab5528c573e637f8",
              "lessThan": "e83eed1bea142c8fe852fd53156845b88252ecd8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae0751ffc77e7f21629970fdab5528c573e637f8",
              "lessThan": "872f486259ae0bc6b73ca4735a15d013241f73e9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/scsi_error.c",
            "drivers/ufs/core/ufshcd.c",
            "include/scsi/scsi_host.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/scsi_error.c",
            "drivers/ufs/core/ufshcd.c",
            "include/scsi/scsi_host.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-26T15:16:54.500",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/872f486259ae0bc6b73ca4735a15d013241f73e9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e83eed1bea142c8fe852fd53156845b88252ecd8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: pair EH runtime PM get and put\n\nshost->eh_noresume is currently consulted twice in one error handling\niteration: once before scsi_autopm_get_host() and once again before\nscsi_autopm_put_host().\n\nThat is racy when a PM-triggered error path flips shost->eh_noresume\nwhile the SCSI EH thread is still running.\n\nThe problem flow looks like this:\nPM path\n  ufshcd_set_dev_pwr_mode()\n    shost->eh_noresume = 1\n    ufshcd_execute_start_stop  <-- trigger EH\n    ...\n    shost->eh_noresume = 0\n\nEH path\n  scsi_error_handler()\n    if (!shost->eh_noresume)\n      scsi_autopm_get_host()  <-- skipped\n    ...\n    if (!shost->eh_noresume)\n       scsi_autopm_put_host()  <-- executed later\n\nIn that case one EH iteration can skip autoresume on entry and still\ndrop a runtime PM reference on exit. That leaves an unmatched runtime PM\nput and can trigger a runtime PM usage count underflow.\n\nFix this by making eh_noresume a regular bool so it can be accessed with\nREAD_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use\nthat snapshot for both runtime PM get and put decisions."
    }
  ],
  "lastModified": "2026-08-26T15:16:54.500",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}