PT-2026-93501 · Linux · Linux Kernel

CVE-2026-89860

·

Published

2026-09-16

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the scsi qla2xxx driver where the functions qla nvme fcp abort() and qla nvme ls abort() call INIT WORK() on the priv->abort work variable immediately before schedule work(). Because INIT WORK() reinitializes the work struct by resetting its list head and clearing the pending bit, issuing an abort more than once for the same command—such as during concurrent transport teardown and a timeout-driven abort—can reinitialize a work item that is already queued. This can lead to corruption of the workqueue list, resulting in system crashes or a looping worker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101421
CVE-2026-89860
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel