{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89860","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.771Z","datePublished":"2026-09-16T10:31:32.263Z","dateUpdated":"2026-09-16T14:39:23.175Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:23.175Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Initialize NVMe abort_work once at submission\n\nqla_nvme_fcp_abort() and qla_nvme_ls_abort() ran INIT_WORK() on\npriv->abort_work immediately before schedule_work(). INIT_WORK()\nreinitializes the work_struct, resetting its list head and clearing the\npending bit. If an abort is issued more than once for the same command\n(for example, concurrent transport teardown and a timeout-driven abort),\nthe second INIT_WORK() reinitializes a work item that is already queued,\nwhich can corrupt the workqueue list and lead to crashes or a looping\nworker.\n\nInitialize priv->abort_work once at command submission, next to the\nexisting per-command spin_lock_init(&priv->cmd_lock), and leave only\nschedule_work() in the abort paths. schedule_work() already does nothing\nwhen the work item is still pending, so a repeated abort no longer\ndisturbs an in-flight work item. The command is not returned to the\ntransport until the final kref_put()/release callback runs after\nabort_work has completed, so the work item is idle before priv is reused\nand the single submission-time INIT_WORK() is safe."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The bug is in the QLogic qla2xxx NVMe-FC initiator abort callbacks. A Fibre Channel peer (compromised NVMe-FC target or zoned SAN device) can stall commands to force timeouts and concurrently drop the link or send LOGO/RSCN so nvme_fc tears down, both of which call ls_abort/fcp_abort. FC is a non-IP fabric, so the vector is adjacent.\nAC:L - A malicious NVMe-FC target controls both sides of the documented race: delaying completions triggers timeout-driven abort while a concurrent link-down or logout triggers teardown abort. INIT_WORK() on still-queued abort_work is then attacker-influenceable under I/O load, so complexity is low.\nPR:N - The attacker is a Fibre Channel peer and needs no host credentials or capabilities. Fabric zoning/WWPN is a topology restriction captured by Adjacent, not an OS privilege, and NVMe in-band authentication is optional and off by default.\nUI:N - With ql2xnvmeenable defaulting to on, an established NVMe-FC association issues keepalives and I/O without user action. The target can stall those commands and flap the link without anyone mounting a volume or running a tool.\nS:U - Impact is kernel workqueue list corruption in the same host kernel that runs qla2xxx. That is ordinary kernel memory-corruption impact, not a VM escape, IOMMU bypass, or other crossed security authority.\nC:H - INIT_WORK() on a queued work_struct resets its list head without unlinking it, corrupting the workqueue and creating a use-after-free of work items. That UAF can be used to read kernel memory, so confidentiality is high.\nI:H - The same workqueue UAF can overwrite adjacent objects and hijack work->func when the worker runs a freed item, yielding an arbitrary-write / control-flow primitive, so integrity is high.\nA:H - The corrupted workqueue can oops, panic, or run a looping worker, crashing or hanging the kernel, so availability is high."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/qla2xxx/qla_nvme.c"],"versions":[{"version":"e473b3074104ee09227cfbba5f872e3ea15dd280","lessThan":"b403700ac62fbf3c310196386e125879a182efcf","status":"affected","versionType":"git"},{"version":"e473b3074104ee09227cfbba5f872e3ea15dd280","lessThan":"6a1b50c4879c2e6a034e8e85f9c055f0eea157c7","status":"affected","versionType":"git"},{"version":"e473b3074104ee09227cfbba5f872e3ea15dd280","lessThan":"67f0d5187c29360388f7e1e503c627ec45d01089","status":"affected","versionType":"git"},{"version":"e473b3074104ee09227cfbba5f872e3ea15dd280","lessThan":"f4aaa4a4e6f1da6f3abfd80e1917bef922287177","status":"affected","versionType":"git"},{"version":"e473b3074104ee09227cfbba5f872e3ea15dd280","lessThan":"7e85f6dbc85616de2172bce8eaf84b387a723cd1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/qla2xxx/qla_nvme.c"],"versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b403700ac62fbf3c310196386e125879a182efcf"},{"url":"https://git.kernel.org/stable/c/6a1b50c4879c2e6a034e8e85f9c055f0eea157c7"},{"url":"https://git.kernel.org/stable/c/67f0d5187c29360388f7e1e503c627ec45d01089"},{"url":"https://git.kernel.org/stable/c/f4aaa4a4e6f1da6f3abfd80e1917bef922287177"},{"url":"https://git.kernel.org/stable/c/7e85f6dbc85616de2172bce8eaf84b387a723cd1"}],"title":"scsi: qla2xxx: Initialize NVMe abort_work once at submission","x_generator":{"engine":"bippy-1.2.0"}}}}