Answer in brief
CVE-2026-93782 records a High severity (CVSS 7.8) vulnerability in vhost-scsi: flush backend after device ioctls. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <981c97d09c6b9560bb12dcc41f11ce59b1a48e97 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <6c1b802e36b05ebd9d41686c4dce6f06966af469 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <22598f55a4c2b510b3df5e69e563387a963222ae || >=0 <6.12.111 || >=0 <6.18.53 | 981c97d09c6b9560bb12dcc41f11ce59b1a48e97, 6c1b802e36b05ebd9d41686c4dce6f06966af469, 22598f55a4c2b510b3df5e69e563387a963222ae, 6.12.111, 6.18.53 |
Published upstream
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descriptors into userspace iovecs when commands are submitted. Target-core completes those commands asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while an in-flight command still retains response iovecs translated through the old table. If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command completion can write the response to an unrelated userspace object. Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device ioctl. This waits for in-flight commands that can still use the old response iovecs before the ioctl returns.
Quoted source text, attributed separately from HOL analysis.