{"id":"CVE-2026-89855","summary":"scsi: qla2xxx: Serialize flash version read in reset handler","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Serialize flash version read in reset handler\n\nThe \"update cache versions without reset\" sysfs reset operation (0x20261)\ncalls get_flash_version(), which reads hardware flash registers, without\nholding ha-\u003eoptrom_mutex. The VPD update path serializes the same call\nunder optrom_mutex, so this reset path can interleave its flash register\naccesses with a concurrent VPD or optrom flash operation and corrupt the\nreads.\n\nHold ha-\u003eoptrom_mutex across the get_flash_version() call to match the\nVPD update path.","modified":"2026-09-18T03:48:33.662234793Z","published":"2026-09-16T10:31:28.836Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89855.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/31bf2714abbb0aa5a8a03d15038f8920e1c74b21"},{"type":"WEB","url":"https://git.kernel.org/stable/c/33735490789e5417851752974c0b1d23125559cd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/75460967619eda720c9a03767729157ffd171d8c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8d116137119371349fb09685fe05413d8fc92efe"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9cef42a073a0bdeee7fb1b47221cda222d330d2a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae979c549cba684e67b6c047140f3a8d2439b298"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f1fc052f2a5890ea6dba80d50254dd6258b13386"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f606ed93de0c4f1e7e3618779e9fad731455314a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89855.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89855"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8c2cf7d4e387d003259488522523807f25576427"},{"fixed":"f1fc052f2a5890ea6dba80d50254dd6258b13386"},{"fixed":"31bf2714abbb0aa5a8a03d15038f8920e1c74b21"},{"fixed":"ae979c549cba684e67b6c047140f3a8d2439b298"},{"fixed":"9cef42a073a0bdeee7fb1b47221cda222d330d2a"},{"fixed":"75460967619eda720c9a03767729157ffd171d8c"},{"fixed":"8d116137119371349fb09685fe05413d8fc92efe"},{"fixed":"33735490789e5417851752974c0b1d23125559cd"},{"fixed":"f606ed93de0c4f1e7e3618779e9fad731455314a"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89855.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.12.0"},{"fixed":"5.10.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.51"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89855.json"}}],"schema_version":"1.9.0"}