{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "2c3dfe3f6ad8daff5acdb01713e4f2b116e78136"
            },
            {
              "fixed": "d09ef32af1e05d79f29b460521a20bc4e6fd2ecf"
            },
            {
              "fixed": "4b7f0a95bfeb1d3673da4c29bbe9872a61bc1a69"
            },
            {
              "fixed": "267533b28ddf2c9223d30ad7e6960fa9e936428e"
            },
            {
              "fixed": "f8d2eb510c063a8ca79a5dc766a4303d3925fe83"
            },
            {
              "fixed": "f6b3bcc7cb2f4c37464958b9fd97dc7f185ea297"
            },
            {
              "fixed": "47272152a13d202d98496208f9bf382c1cf4d4fb"
            },
            {
              "fixed": "d556f899964d184e6cb788f3fa9dcddcafe1ab2d"
            },
            {
              "fixed": "793cedee296fd819bfadc2a7ec4d52faf9c09a0a"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.6.23"
            },
            {
              "fixed": "5.10.270"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.221"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.188"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.157"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.110"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.51"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89861.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()\n\nIn the format 1 path, the virtual port is located on ha-\u003evp_list while\nholding vport_slock, but the lock is dropped before vp is used:\nqla_update_host_map() is called and VP_IDX_ACQUIRED/REGISTER_FC4_NEEDED/\nREGISTER_FDMI_NEEDED are set on vp. No reference is taken across that\nwindow, so a concurrent qla24xx_deallocate_vp_id() can tear the vport\ndown and free it, leading to a use-after-free.\n\nTake a vport reference (vref_count) under vport_slock when the matching\nvp is found, and drop it after the last use of\nvp. qla24xx_deallocate_vp_id() waits for vref_count to reach zero before\nunlinking and freeing the vport, so the pointer stays valid. This\nmatches the reference idiom already used by the other ha-\u003evp_list\ntraversals.",
  "id": "CVE-2026-89861",
  "modified": "2026-09-18T03:30:31.540865155Z",
  "published": "2026-09-16T10:31:32.987Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/267533b28ddf2c9223d30ad7e6960fa9e936428e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/47272152a13d202d98496208f9bf382c1cf4d4fb"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4b7f0a95bfeb1d3673da4c29bbe9872a61bc1a69"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/793cedee296fd819bfadc2a7ec4d52faf9c09a0a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d09ef32af1e05d79f29b460521a20bc4e6fd2ecf"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d556f899964d184e6cb788f3fa9dcddcafe1ab2d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f6b3bcc7cb2f4c37464958b9fd97dc7f185ea297"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f8d2eb510c063a8ca79a5dc766a4303d3925fe83"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89861.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89861"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()"
}