๐Ÿ” CVE Alert

CVE-2026-89860

UNKNOWN 0.0

scsi: qla2xxx: Initialize NVMe abort_work once at submission

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Initialize NVMe abort_work once at submission qla_nvme_fcp_abort() and qla_nvme_ls_abort() ran INIT_WORK() on priv->abort_work immediately before schedule_work(). INIT_WORK() reinitializes the work_struct, resetting its list head and clearing the pending bit. If an abort is issued more than once for the same command (for example, concurrent transport teardown and a timeout-driven abort), the second INIT_WORK() reinitializes a work item that is already queued, which can corrupt the workqueue list and lead to crashes or a looping worker. Initialize priv->abort_work once at command submission, next to the existing per-command spin_lock_init(&priv->cmd_lock), and leave only schedule_work() in the abort paths. schedule_work() already does nothing when the work item is still pending, so a repeated abort no longer disturbs an in-flight work item. The command is not returned to the transport until the final kref_put()/release callback runs after abort_work has completed, so the work item is idle before priv is reused and the single submission-time INIT_WORK() is safe.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
e473b3074104ee09227cfbba5f872e3ea15dd280 < b403700ac62fbf3c310196386e125879a182efcf e473b3074104ee09227cfbba5f872e3ea15dd280 < 6a1b50c4879c2e6a034e8e85f9c055f0eea157c7 e473b3074104ee09227cfbba5f872e3ea15dd280 < 67f0d5187c29360388f7e1e503c627ec45d01089 e473b3074104ee09227cfbba5f872e3ea15dd280 < f4aaa4a4e6f1da6f3abfd80e1917bef922287177 e473b3074104ee09227cfbba5f872e3ea15dd280 < 7e85f6dbc85616de2172bce8eaf84b387a723cd1
Linux / Linux
4.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b403700ac62fbf3c310196386e125879a182efcf git.kernel.org: https://git.kernel.org/stable/c/6a1b50c4879c2e6a034e8e85f9c055f0eea157c7 git.kernel.org: https://git.kernel.org/stable/c/67f0d5187c29360388f7e1e503c627ec45d01089 git.kernel.org: https://git.kernel.org/stable/c/f4aaa4a4e6f1da6f3abfd80e1917bef922287177 git.kernel.org: https://git.kernel.org/stable/c/7e85f6dbc85616de2172bce8eaf84b387a723cd1