« Volver al listado

CVE-2026-72082

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()

When efct_hw_reqtag_alloc() fails in efct_hw_io_abort(), the error path returns -ENOSPC without releasing the reference obtained via kref_get_unless_zero() earlier in the function. All other error paths correctly drop the reference. This causes a permanent reference leak on the io_to_abort object.

Additionally, the abort_in_progress flag is left set to true on this path, which means future abort attempts for the same I/O will immediately return -EINPROGRESS even though the abort was never submitted, effectively blocking recovery.

Leer descripción completaMostrar menos

Fix this by adding the missing kref_put() call and reset abort_in_progress to false, matching the cleanup done in the efct_hw_wq_write() failure path below.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72082",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "63de51327a64c74e85611a0161eaae71256a3b6d",
              "lessThan": "cf97ea7b164a1881c7219f5222219c9d0fac4204",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "63de51327a64c74e85611a0161eaae71256a3b6d",
              "lessThan": "1c6e186c722cfa9a58ebe841f91ab2ddf8570cc7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "63de51327a64c74e85611a0161eaae71256a3b6d",
              "lessThan": "62cf39a9770a6f29df59fd0edb0a05234a8b07f2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "63de51327a64c74e85611a0161eaae71256a3b6d",
              "lessThan": "faa59add4808fbf92e7d15bfd8770d2682c2b953",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "63de51327a64c74e85611a0161eaae71256a3b6d",
              "lessThan": "9b871369cbb4532f6715e044d6b9c4ceb036e5b6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "63de51327a64c74e85611a0161eaae71256a3b6d",
              "lessThan": "747eaead2db298abfda2aa505f6d03775b40fe5f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "63de51327a64c74e85611a0161eaae71256a3b6d",
              "lessThan": "2c007acf7b31c39c08ce4959451ad00b19be4c1f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/elx/efct/efct_hw.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/elx/efct/efct_hw.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:18.250",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1c6e186c722cfa9a58ebe841f91ab2ddf8570cc7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2c007acf7b31c39c08ce4959451ad00b19be4c1f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/62cf39a9770a6f29df59fd0edb0a05234a8b07f2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/747eaead2db298abfda2aa505f6d03775b40fe5f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b871369cbb4532f6715e044d6b9c4ceb036e5b6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cf97ea7b164a1881c7219f5222219c9d0fac4204",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/faa59add4808fbf92e7d15bfd8770d2682c2b953",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: elx: efct: Fix refcount leak in efct_hw_io_abort()\n\nWhen efct_hw_reqtag_alloc() fails in efct_hw_io_abort(), the error path\nreturns -ENOSPC without releasing the reference obtained via\nkref_get_unless_zero() earlier in the function. All other error paths\ncorrectly drop the reference. This causes a permanent reference leak on the\nio_to_abort object.\n\nAdditionally, the abort_in_progress flag is left set to true on this path,\nwhich means future abort attempts for the same I/O will immediately return\n-EINPROGRESS even though the abort was never submitted, effectively\nblocking recovery.\n\nFix this by adding the missing kref_put() call and reset abort_in_progress\nto false, matching the cleanup done in the efct_hw_wq_write() failure path\nbelow."
    }
  ],
  "lastModified": "2026-08-17T06:18:06.940",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}