{"id":"CVE-2026-89860","published":"2026-09-16T11:16:53.957","lastModified":"2026-09-16T15:18:13.790","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Initialize NVMe abort_work once at submission\n\nqla_nvme_fcp_abort() and qla_nvme_ls_abort() ran INIT_WORK() on\npriv->abort_work immediately before schedule_work(). INIT_WORK()\nreinitializes the work_struct, resetting its list head and clearing the\npending bit. If an abort is issued more than once for the same command\n(for example, concurrent transport teardown and a timeout-driven abort),\nthe second INIT_WORK() reinitializes a work item that is already queued,\nwhich can corrupt the workqueue list and lead to crashes or a looping\nworker.\n\nInitialize priv->abort_work once at command submission, next to the\nexisting per-command spin_lock_init(&priv->cmd_lock), and leave only\nschedule_work() in the abort paths. schedule_work() already does nothing\nwhen the work item is still pending, so a repeated abort no longer\ndisturbs an in-flight work item. The command is not returned to the\ntransport until the final kref_put()/release callback runs after\nabort_work has completed, so the work item is idle before priv is reused\nand the single submission-time INIT_WORK() is safe.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/67f0d5187c29360388f7e1e503c627ec45d01089","tags":[]},{"url":"https://git.kernel.org/stable/c/6a1b50c4879c2e6a034e8e85f9c055f0eea157c7","tags":[]},{"url":"https://git.kernel.org/stable/c/7e85f6dbc85616de2172bce8eaf84b387a723cd1","tags":[]},{"url":"https://git.kernel.org/stable/c/b403700ac62fbf3c310196386e125879a182efcf","tags":[]},{"url":"https://git.kernel.org/stable/c/f4aaa4a4e6f1da6f3abfd80e1917bef922287177","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability in the Linux kernel's qla2xxx driver allows for potential corruption of the workqueue list, leading to crashes or looping worker issues when an abort is issued multiple times for the same command.","exploitability":"Exploitation requires the ability to issue multiple abort commands for the same command, which is a precondition. The vulnerability is not easily exploitable without this condition.","blast_radius":"If exploited, the impact is limited to the system running the affected Linux kernel version, potentially leading to system crashes or denial of service.","remediation":"Upgrade to the specific version 5.10.109 or later, as published in the advisory.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["kernel","workqueue","crash","workitem"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:16:01.277Z"}}