Answer in brief
CVE-2026-89855 records a Unknown severity vulnerability in scsi: qla2xxx: Serialize flash version read in reset handler. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8c2cf7d4e387d003259488522523807f25576427 <f1fc052f2a5890ea6dba80d50254dd6258b13386 || >=8c2cf7d4e387d003259488522523807f25576427 <31bf2714abbb0aa5a8a03d15038f8920e1c74b21 || >=8c2cf7d4e387d003259488522523807f25576427 <ae979c549cba684e67b6c047140f3a8d2439b298 || >=8c2cf7d4e387d003259488522523807f25576427 <9cef42a073a0bdeee7fb1b47221cda222d330d2a || >=8c2cf7d4e387d003259488522523807f25576427 <75460967619eda720c9a03767729157ffd171d8c || >=8c2cf7d4e387d003259488522523807f25576427 <8d116137119371349fb09685fe05413d8fc92efe || >=8c2cf7d4e387d003259488522523807f25576427 <33735490789e5417851752974c0b1d23125559cd || >=8c2cf7d4e387d003259488522523807f25576427 <f606ed93de0c4f1e7e3618779e9fad731455314a | f1fc052f2a5890ea6dba80d50254dd6258b13386, 31bf2714abbb0aa5a8a03d15038f8920e1c74b21, ae979c549cba684e67b6c047140f3a8d2439b298, 9cef42a073a0bdeee7fb1b47221cda222d330d2a, 75460967619eda720c9a03767729157ffd171d8c, 8d116137119371349fb09685fe05413d8fc92efe, 33735490789e5417851752974c0b1d23125559cd, f606ed93de0c4f1e7e3618779e9fad731455314a |
| Linux/Linuxgeneric | 3.12 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in reset handler The "update cache versions without reset" sysfs reset operation (0x20261) calls get_flash_version(), which reads hardware flash registers, without holding ha->optrom_mutex. The VPD update path serializes the same call under optrom_mutex, so this reset path can interleave its flash register accesses with a concurrent VPD or optrom flash operation and corrupt the reads. Hold ha->optrom_mutex across the get_flash_version() call to match the VPD update path.
Quoted source text, attributed separately from HOL analysis.