CVE-2026-89853

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the buffer) under hardware_lock and never take fce_mutex. A debugfs FCE disable could therefore free the DMA buffer between a dump's NULL check and its copy, resulting in a use-after-free. Unpublish ha->fce under hardware_lock, then release the lock and free the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either completes its check and copy with the buffer still valid, or observes ha->fce == NULL and skips it.

Package Linux Kernel
Published 2026-09-16
Last modified 2026-09-16
Patch available
Yes

Affected versions

Linux kernel versions 5.10.235, 5.15.179, 6.1.129, 6.6.78, 6.12.14, 6.13.3, 6.14 and later are affected. Fixed in 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.110, 6.18.51, 7.2.5, 7.3-rc1 and their respective stable series.

Affected from
≥ 5.10.235 ≥ 5.15.179 ≥ 6.1.129 ≥ 6.6.78 ≥ 6.12.14 ≥ 6.13.3 ≥ 6.14
Fixed in
✓ 5.10.270 5.10.x ✓ 5.15.221 5.15.x ✓ 6.1.188 6.1.x ✓ 6.6.157 6.6.x ✓ 6.12.110 6.12.x ✓ 6.18.51 6.18.x ✓ 7.2.5 7.2.x ✓ 7.3-rc1

Frequently asked questions

  • What is CVE-2026-89853?

    CVE-2026-89853 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.10.235 onward and has been patched in 5.10.270, 5.15.221, 6.1.188 and others. CVE-2026-89853 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-89853?

    Yes. CVE-2026-89853 has been patched. Fixed versions include 5.10.270, 5.15.221, 6.1.188 and others. If you are running Linux kernel 5.10.235 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-89853 actively exploited?

    No. CVE-2026-89853 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.