{"id":"CVE-2026-92479","summary":"scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: Avoid NULL CQE dereference when reporting invalid tags\n\nThe single-doorbell completion path can call ufshcd_compl_one_cqe() with a\nNULL CQE. If no command is associated with the completion tag, the warning\nmessage dereferences the CQE while reporting the error.  Avoid that\ndereference and include the invalid tag in the warning.","modified":"2026-09-19T03:47:26.514026784Z","published":"2026-09-17T16:09:57.058Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92479.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/331bda797e6afc143127ce72b1469d73316f49b4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a769095d1d74ebac2b1474c56bbd29bb0b9ed5a7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92479.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92479"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"22089c218037ca7cd50d4fa20e8b5bd746a9b397"},{"fixed":"a769095d1d74ebac2b1474c56bbd29bb0b9ed5a7"},{"fixed":"331bda797e6afc143127ce72b1469d73316f49b4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92479.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92479.json"}}],"schema_version":"1.9.0"}