CVE-2026-89848
HighIn the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Quiesce response IRQ before freeing request queue qla2xxx_delete_qpair() deletes the request queue before the response queue. qla25xx_delete_req_que() frees the request queue memory (kfree(req) in qla25xx_free_req_que()), but the response-queue MSI-X is only released later, in qla25xx_free_rsp_que(). In that window the response interrupt can still fire, qla2xxx_msix_rsp_q() queues qpair->q_work, and qla_do_work() -> qla24xx_process_response_queue() dereferences the now-freed rsp->req (LOGINOUT/CT/ELS entries and the status path), a use-after-free. The cancel_work_sync() added for the qpair teardown lives in the response free path, which runs after the request queue is already freed, so it does not protect rsp->req. Release the response-queue interrupt and flush qpair->q_work before deleting the request queue, so no late completion can reach the freed request queue. Clearing have_irq makes the subsequent qla25xx_free_rsp_que() skip its free_irq(), and the firmware queue-delete order (request then response) is preserved; the request-delete mailbox completes on the default vector and is unaffected by dropping the qpair response interrupt early.
CVSS 3.1 score
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected versions
Linux kernel versions
4.10
and later are affected. Fixed in
6.6.157,
6.12.110,
6.18.51,
7.2.5,
7.3-rc1
and their respective stable series.
References
5 totalFrequently asked questions
-
What is CVE-2026-89848?
CVE-2026-89848 is a High severity Linux kernel vulnerability with a CVSS score of 8.1 out of 10 . It affects Linux kernel versions from 4.10 onward and has been patched in 6.6.157, 6.12.110, 6.18.51 and others. CVE-2026-89848 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2026-89848?
CVE-2026-89848 has a CVSS score of 8.1 out of 10, rated High severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. -
Is there a patch available for CVE-2026-89848?
Yes. CVE-2026-89848 has been patched. Fixed versions include 6.6.157, 6.12.110, 6.18.51 and others. If you are running Linux kernel 4.10 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-89848 actively exploited?
No. CVE-2026-89848 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.