๐Ÿ” CVE Alert

CVE-2026-64103

UNKNOWN 0.0

scsi: isci: Fix use-after-free in device removal path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: isci: Fix use-after-free in device removal path The ISCI completion tasklet is initialized in isci_host_alloc() (drivers/scsi/isci/init.c:496) and scheduled from both MSI-X and legacy interrupt handlers (drivers/scsi/isci/host.c:223,613). isci_host_deinit() stops the controller and waits for stop completion, but it never kills completion_tasklet before teardown continues. A top-of-function tasklet_kill() is not sufficient here: interrupts are only disabled when isci_host_stop_complete() runs, so until wait_for_stop() returns the IRQ handlers can still requeue the tasklet. The tasklet callback also re-enables interrupts after draining completions, so killing the tasklet before the source is quiesced leaves the same race open. Once wait_for_stop() returns, no further IRQ-driven scheduling can occur. Kill completion_tasklet there so teardown cannot race a queued tasklet running on a dead ihost. On remove or unload, the stale callback can otherwise dereference ihost and touch ihost->smu_registers after the host lifetime ends. A UML + KASAN analogue reproduced the failure class both with no tasklet_kill() and with tasklet_kill() placed before source quiesce, and stayed clean once the kill happened after quiescing the scheduling source. This mirrors commit f6ab594672d4 ("scsi: aic94xx: fix use-after-free in device removal path"), but ISCI needs the kill after wait_for_stop().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
6f231dda68080759f1aed3769896e94c73099f0f < 1412995e10c74644b47f242aea6e4f3d4180e806 6f231dda68080759f1aed3769896e94c73099f0f < a83d3e4daba40d49324cec1c51ed261e1ea48cf1 6f231dda68080759f1aed3769896e94c73099f0f < ab2266601a875982f2d2033f41e070a6d5e615e2 6f231dda68080759f1aed3769896e94c73099f0f < 309c6058622d080fe8c2fab87c30da82d834d989 6f231dda68080759f1aed3769896e94c73099f0f < cb9e72c50e6c81a5903f27e0b397ce8525d7539b 6f231dda68080759f1aed3769896e94c73099f0f < b9ff8631006233ba246828ac70409d2cb2da38d3 6f231dda68080759f1aed3769896e94c73099f0f < 6d40f2f103bb30f52f3dbadbe2c3fdf274a9763c 6f231dda68080759f1aed3769896e94c73099f0f < b52a8d52c3125ec9a93106ed816582368de34426
Linux / Linux
3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/1412995e10c74644b47f242aea6e4f3d4180e806 git.kernel.org: https://git.kernel.org/stable/c/a83d3e4daba40d49324cec1c51ed261e1ea48cf1 git.kernel.org: https://git.kernel.org/stable/c/ab2266601a875982f2d2033f41e070a6d5e615e2 git.kernel.org: https://git.kernel.org/stable/c/309c6058622d080fe8c2fab87c30da82d834d989 git.kernel.org: https://git.kernel.org/stable/c/cb9e72c50e6c81a5903f27e0b397ce8525d7539b git.kernel.org: https://git.kernel.org/stable/c/b9ff8631006233ba246828ac70409d2cb2da38d3 git.kernel.org: https://git.kernel.org/stable/c/6d40f2f103bb30f52f3dbadbe2c3fdf274a9763c git.kernel.org: https://git.kernel.org/stable/c/b52a8d52c3125ec9a93106ed816582368de34426