CVE-2026-89853: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the buffer) under hardware_lock and never take fce_mutex. A debugfs FCE disable could therefore free the DMA buffer between a dump's NULL check and its copy, resulting in a use-after-free. Unpublish ha->fce under hardware_lock, then release the lock and free the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either completes its check and copy with the buffer still valid, or observes ha->fce == NULL and skips it.
Affected products
- Linux Linux: from 5.10.235, before 5.10.270 (fixed in 5.10.270); from 5.15.179, before 5.15.221 (fixed in 5.15.221); from 6.1.129, before 6.1.188 (fixed in 6.1.188); from 6.6.78, before 6.6.157 (fixed in 6.6.157); from 6.12.14, before 6.12.110 (fixed in 6.12.110); from 6.13.3, before 6.14 (fixed in 6.14); …
Published 2026-09-16. Last modified 2026-09-16.