« Volver al listado

CVE-2026-89862

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix BSG job leak on validate flash image error path

qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally, telling the FC BSG transport (fc_bsg_host_dispatch()) that the driver owns and will complete the request. But bsg_job_done() is guarded by "if (!rval)", so on the error path (rval == -EINVAL) neither the driver nor the transport completes the job. The request dangles until it times out, leaking block layer resources.

Commit c2c68225b145 ("scsi: qla2xxx: Fix bsg_done() causing double free") added the "if (!rval)" guard to a batch of BSG handlers.

Leer descripción completaMostrar menos

That is correct for handlers that also return the error code (the transport then completes the job once via fail_host_msg), but this function returns QLA_SUCCESS unconditionally, so the guard turned a correct single completion into a leak.

Always call bsg_job_done(): bsg_reply->result is DID_OK and the error is reported in vendor_rsp[0], and since the function returns 0 the transport will not complete the job a second time.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89862",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0",
              "lessThan": "e25241f9fa01fb0c088381a156d84a725b71c1ef",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0",
              "lessThan": "0fb52cc632464b0cd07f970341330466d772efe1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "057a5bdc481e58ab853117254867ffb22caf9f6e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f2bbb4db0e4a4fbd5e649c0b5d8733f61da24720",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27ac9679c43a09e54e2d9aae9980ada045b428e0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "74e7458537cd9349cf019862e51491f670871707",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "871f6236da96c4a9712b8a29d7f555f767a47e95",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "31f33b856d2324d86bcaef295f4d210477a1c018",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "708003e1bc857dd014d4c44278d7d77c26f91b1c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.251",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.201",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.164",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.127",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.74",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.13",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.3",
              "lessThan": "6.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_bsg.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_bsg.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:54.237",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0fb52cc632464b0cd07f970341330466d772efe1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e25241f9fa01fb0c088381a156d84a725b71c1ef",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix BSG job leak on validate flash image error path\n\nqla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally,\ntelling the FC BSG transport (fc_bsg_host_dispatch()) that the driver\nowns and will complete the request. But bsg_job_done() is guarded by \"if\n(!rval)\", so on the error path (rval == -EINVAL) neither the driver nor\nthe transport completes the job. The request dangles until it times out,\nleaking block layer resources.\n\nCommit c2c68225b145 (\"scsi: qla2xxx: Fix bsg_done() causing double\nfree\") added the \"if (!rval)\" guard to a batch of BSG handlers. That is\ncorrect for handlers that also return the error code (the transport then\ncompletes the job once via fail_host_msg), but this function returns\nQLA_SUCCESS unconditionally, so the guard turned a correct single\ncompletion into a leak.\n\nAlways call bsg_job_done(): bsg_reply->result is DID_OK and the error is\nreported in vendor_rsp[0], and since the function returns 0 the\ntransport will not complete the job a second time."
    }
  ],
  "lastModified": "2026-09-16T11:16:54.237",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}