8.8

CVE-2026-89860

scsi: qla2xxx: Initialize NVMe abort_work once at submission

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Initialize NVMe abort_work once at submission

qla_nvme_fcp_abort() and qla_nvme_ls_abort() ran INIT_WORK() on
priv->abort_work immediately before schedule_work(). INIT_WORK()
reinitializes the work_struct, resetting its list head and clearing the
pending bit. If an abort is issued more than once for the same command
(for example, concurrent transport teardown and a timeout-driven abort),
the second INIT_WORK() reinitializes a work item that is already queued,
which can corrupt the workqueue list and lead to crashes or a looping
worker.

Initialize priv->abort_work once at command submission, next to the
existing per-command spin_lock_init(&priv->cmd_lock), and leave only
schedule_work() in the abort paths. schedule_work() already does nothing
when the work item is still pending, so a repeated abort no longer
disturbs an in-flight work item. The command is not returned to the
transport until the final kref_put()/release callback runs after
abort_work has completed, so the work item is idle before priv is reused
and the single submission-time INIT_WORK() is safe.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e473b3074104ee09227cfbba5f872e3ea15dd280
Version < b403700ac62fbf3c310196386e125879a182efcf
Status affected
Version e473b3074104ee09227cfbba5f872e3ea15dd280
Version < 6a1b50c4879c2e6a034e8e85f9c055f0eea157c7
Status affected
Version e473b3074104ee09227cfbba5f872e3ea15dd280
Version < 67f0d5187c29360388f7e1e503c627ec45d01089
Status affected
Version e473b3074104ee09227cfbba5f872e3ea15dd280
Version < f4aaa4a4e6f1da6f3abfd80e1917bef922287177
Status affected
Version e473b3074104ee09227cfbba5f872e3ea15dd280
Version < 7e85f6dbc85616de2172bce8eaf84b387a723cd1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.17
Status affected
Version 0
Version < 4.17
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.273
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b403700ac62fbf3c310196386e125879a182efcf
https://git.kernel.org/stable/c/6a1b50c4879c2e6a034e8e85f9c055f0eea157c7
https://git.kernel.org/stable/c/67f0d5187c29360388f7e1e503c627ec45d01089
https://git.kernel.org/stable/c/f4aaa4a4e6f1da6f3abfd80e1917bef922287177
https://git.kernel.org/stable/c/7e85f6dbc85616de2172bce8eaf84b387a723cd1