Answer in brief
CVE-2026-74555 records a Unknown severity vulnerability in scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fbefe22811c3140a686e407e114789ebf328a9a2 <e50a6523a603594a6d92cdecfe11997d639410a3 || >=fbefe22811c3140a686e407e114789ebf328a9a2 <c391b5899dd46485a5893696c12ae3e95a3a7325 || >=fbefe22811c3140a686e407e114789ebf328a9a2 <9e24b47ef81d43b3fb1b14294f09991640c79fcc || >=fbefe22811c3140a686e407e114789ebf328a9a2 <b9c44a14062093e9fc2d6bddc696cfceadb482d7 || >=fbefe22811c3140a686e407e114789ebf328a9a2 <3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845 | e50a6523a603594a6d92cdecfe11997d639410a3, c391b5899dd46485a5893696c12ae3e95a3a7325, 9e24b47ef81d43b3fb1b14294f09991640c79fcc, b9c44a14062093e9fc2d6bddc696cfceadb482d7, 3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845 |
| Linux/Linuxgeneric | 5.17 | Not reported |
| Linux/Linuxgeneric | >=fbefe22811c3140a686e407e114789ebf328a9a2 <09357f067122e2e28ec52e27013a1660a1571618 || >=fbefe22811c3140a686e407e114789ebf328a9a2 <e50a6523a603594a6d92cdecfe11997d639410a3 || >=fbefe22811c3140a686e407e114789ebf328a9a2 <c391b5899dd46485a5893696c12ae3e95a3a7325 || >=fbefe22811c3140a686e407e114789ebf328a9a2 <9e24b47ef81d43b3fb1b14294f09991640c79fcc || >=fbefe22811c3140a686e407e114789ebf328a9a2 <b9c44a14062093e9fc2d6bddc696cfceadb482d7 || >=fbefe22811c3140a686e407e114789ebf328a9a2 <3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845 | 09357f067122e2e28ec52e27013a1660a1571618, e50a6523a603594a6d92cdecfe11997d639410a3, c391b5899dd46485a5893696c12ae3e95a3a7325, 9e24b47ef81d43b3fb1b14294f09991640c79fcc, b9c44a14062093e9fc2d6bddc696cfceadb482d7, 3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845 |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race Commit fbefe22811c3 ("scsi: libsas: Don't always drain event workqueue for HA resume") introduced sas_resume_ha_no_sync() to avoid a deadlock: the PHYE_RESUME_TIMEOUT handler, running on the HA event workqueue, calls sas_deform_port() -> sas_destruct_devices(), which removes SCSI devices and waits for the host to become runtime-active. But the host cannot resume until sas_resume_ha() -> sas_drain_work() returns, and the drain is blocked on that very handler. However skipping the drain reintroduces a race: hisi_sas returns from resume before all PHY UP work and libsas discovery work finish. The controller may then autosuspend while disks are still waking up. The disks issue IO to a suspended controller, the IO fails, and the disks get disabled. Fix the deadlock at its source by moving the PHYE_RESUME_TIMEOUT notification to after sas_drain_work(). By then the host resume is about to complete, so device removal through device_link no longer blocks on the resume and the cycle is broken. With the deadlock gone, restore sas_resume_ha() (the draining variant) in hisi_sas and remove sas_resume_ha_no_sync(). The reorder is safe for the other libsas consumers (isci, pm8001, aic94xx, mvsas). During suspend, sas_suspend_devices() calls sas_notify_lldd_dev_gone() for each device, which sets dev->lldd_dev to NULL. When scsi_unblock_requests re-enables I/O in resume, any I/O to a timed-out phy's disk is immediately rejected by the LLDD before reaching hardware: isci returns SAS_DEVICE_UNKNOWN (mapped to DID_BAD_TARGET), and pm8001 returns SAS_PHY_DOWN (mapped to DID_NO_CONNECT). Both complete directly via scsi_done() without entering SCSI EH. This is identical in both the old and new ordering since lldd_dev_gone runs during suspend, before resume. The reorder only affects when the PHYE_RESUME_TIMEOUT handler runs (synchronized by sas_drain_work() vs. asynchronous after resume returns), not whether I/O can reach the device. aic94xx and mvsas do not register any PM ops and never reach this code path.
Quoted source text, attributed separately from HOL analysis.