« Volver al listado

CVE-2026-89854

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix cs84xx use-after-free on host teardown

qla84xx_put_chip() drops the last reference to ha->cs84xx and frees it via __qla84xx_chip_release() without clearing ha->cs84xx. During teardown it ran before scsi_remove_host(), which is what removes the 84xx_fw_version host sysfs attribute. A concurrent read of that attribute in the window between the two calls executes qla24xx_84xx_fw_version_show(), which dereferences the freed ha->cs84xx, resulting in a use-after-free.

Move qla84xx_put_chip() to after scsi_remove_host() in both qla2x00_remove_one() and qla2x00_disable_board_on_pci_error().

Leer descripción completaMostrar menos

Once scsi_remove_host() returns, the sysfs attribute is gone and kernfs has drained any in-flight show(), so no reader can touch cs84xx; the put still runs before the host and ha are freed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad use-after-free en kernel de Linux accesible con privilegios locales (PR:L, AV:L). La lectura de atributo sysfs tras liberación de memoria permite denegación de servicio por lectura de puntero inválido o corrupción de datos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89854",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fe1b806f4f7172b1eae18ddeebb7d8fb351043f7",
              "lessThan": "8c1ebcade6aac58137f2645b579894301febabf3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe1b806f4f7172b1eae18ddeebb7d8fb351043f7",
              "lessThan": "1d8bbc4344b9367d9d54731475d745fbc9ea28f2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe1b806f4f7172b1eae18ddeebb7d8fb351043f7",
              "lessThan": "2c3b17ee53f034936f7398dbf4d143e608b7c35c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe1b806f4f7172b1eae18ddeebb7d8fb351043f7",
              "lessThan": "ae09260be7454ed7630a913f147591a25e3a9d09",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe1b806f4f7172b1eae18ddeebb7d8fb351043f7",
              "lessThan": "fcf0804dfe05862007189ac9dc4dc2063be36de1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe1b806f4f7172b1eae18ddeebb7d8fb351043f7",
              "lessThan": "8286a9095fb59751fba171afa2b4f590271c87d5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe1b806f4f7172b1eae18ddeebb7d8fb351043f7",
              "lessThan": "122bf170c94a3797531b12fee580639a5dc893ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe1b806f4f7172b1eae18ddeebb7d8fb351043f7",
              "lessThan": "33d102102d925357c5fd172dd6672a27d74b3215",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_os.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_os.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:53.180",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/122bf170c94a3797531b12fee580639a5dc893ed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1d8bbc4344b9367d9d54731475d745fbc9ea28f2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2c3b17ee53f034936f7398dbf4d143e608b7c35c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/33d102102d925357c5fd172dd6672a27d74b3215",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8286a9095fb59751fba171afa2b4f590271c87d5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8c1ebcade6aac58137f2645b579894301febabf3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ae09260be7454ed7630a913f147591a25e3a9d09",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fcf0804dfe05862007189ac9dc4dc2063be36de1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix cs84xx use-after-free on host teardown\n\nqla84xx_put_chip() drops the last reference to ha->cs84xx and frees it via\n__qla84xx_chip_release() without clearing ha->cs84xx. During teardown it ran\nbefore scsi_remove_host(), which is what removes the 84xx_fw_version host\nsysfs attribute. A concurrent read of that attribute in the window between\nthe two calls executes qla24xx_84xx_fw_version_show(), which dereferences\nthe freed ha->cs84xx, resulting in a use-after-free.\n\nMove qla84xx_put_chip() to after scsi_remove_host() in both\nqla2x00_remove_one() and qla2x00_disable_board_on_pci_error(). Once\nscsi_remove_host() returns, the sysfs attribute is gone and kernfs has\ndrained any in-flight show(), so no reader can touch cs84xx; the put still\nruns before the host and ha are freed."
    }
  ],
  "lastModified": "2026-09-16T15:18:13.367",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}