UNKNOWN NVD
CVE-2026-89855
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in reset handler The "update cache versions wi
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Serialize flash version read in reset handler
The "update cache versions without reset" sysfs reset operation (0x20261)
calls get_flash_version(), which reads hardware flash registers, without
holding ha->optrom_mutex. The VPD update path serializes the same call
under optrom_mutex, so this reset path can interleave its flash register
accesses with a concurrent VPD or optrom flash operation and corrupt the
reads.
Hold ha->optrom_mutex across the get_flash_version() call to match the
VPD update path.
References
- https://git.kernel.org/stable/c/31bf2714abbb0aa5a8a03d15038f8920e1c74b21
- https://git.kernel.org/stable/c/33735490789e5417851752974c0b1d23125559cd
- https://git.kernel.org/stable/c/75460967619eda720c9a03767729157ffd171d8c
- https://git.kernel.org/stable/c/8d116137119371349fb09685fe05413d8fc92efe
- https://git.kernel.org/stable/c/9cef42a073a0bdeee7fb1b47221cda222d330d2a
This unknown severity vulnerability was published on 2026-09-16 via NVD.
vulnfeed aggregates 14391 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.