CVE-2026-89844

High

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition qla24xx_report_id_acquisition() format-1 handling drops vport_slock after taking the vport reference and then calls qla_update_host_map() without the lock. That reaches qla_update_vp_map(), which mutates the ha->host_map btree via btree_insert32()/btree_update32()/btree_remove32() and is documented to require vport_slock to be held by the caller. Running it unlocked can race concurrent host_map updates and corrupt the btree. The format-2 path in the same function already wraps its host_map update (SET_AL_PA) in vport_slock; the format-1 path is the lone outlier. Hold vport_slock across the format-1 qla_update_host_map() call to honor the documented locking contract. The vref_count taken in the loop keeps the vport valid, so this only adds the missing host_map serialization.

Package Linux Kernel
Published 2026-09-16
Last modified 2026-09-16
CVSS version 3.1
Patch available
Yes

CVSS 3.1 score

8.8

out of 10
High
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected versions

Linux kernel versions 6.3 and later are affected. Fixed in 6.6.157, 6.12.110, 6.18.51, 7.2.5, 7.3-rc1 and their respective stable series.

Affected from
≥ 6.3
Fixed in
✓ 6.6.157 6.6.x ✓ 6.12.110 6.12.x ✓ 6.18.51 6.18.x ✓ 7.2.5 7.2.x ✓ 7.3-rc1

Frequently asked questions

  • What is CVE-2026-89844?

    CVE-2026-89844 is a High severity Linux kernel vulnerability with a CVSS score of 8.8 out of 10 . It affects Linux kernel versions from 6.3 onward and has been patched in 6.6.157, 6.12.110, 6.18.51 and others. CVE-2026-89844 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • What is the CVSS score for CVE-2026-89844?

    CVE-2026-89844 has a CVSS score of 8.8 out of 10, rated High severity (CVSS 3.1). The vector string is CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H .

  • Is there a patch available for CVE-2026-89844?

    Yes. CVE-2026-89844 has been patched. Fixed versions include 6.6.157, 6.12.110, 6.18.51 and others. If you are running Linux kernel 6.3 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-89844 actively exploited?

    No. CVE-2026-89844 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.