All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-64103: scsi: isci: Fix use-after-free in device removal path
@ 2026-07-19 15:39 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-07-19 15:39 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

scsi: isci: Fix use-after-free in device removal path

The ISCI completion tasklet is initialized in isci_host_alloc()
(drivers/scsi/isci/init.c:496) and scheduled from both MSI-X and legacy
interrupt handlers (drivers/scsi/isci/host.c:223,613).

isci_host_deinit() stops the controller and waits for stop completion,
but it never kills completion_tasklet before teardown continues. A
top-of-function tasklet_kill() is not sufficient here: interrupts are
only disabled when isci_host_stop_complete() runs, so until
wait_for_stop() returns the IRQ handlers can still requeue the
tasklet. The tasklet callback also re-enables interrupts after draining
completions, so killing the tasklet before the source is quiesced leaves
the same race open.

Once wait_for_stop() returns, no further IRQ-driven scheduling can
occur. Kill completion_tasklet there so teardown cannot race a queued
tasklet running on a dead ihost. On remove or unload, the stale callback
can otherwise dereference ihost and touch ihost->smu_registers after the
host lifetime ends.

A UML + KASAN analogue reproduced the failure class both with no
tasklet_kill() and with tasklet_kill() placed before source quiesce, and
stayed clean once the kill happened after quiescing the scheduling
source.

This mirrors commit f6ab594672d4 ("scsi: aic94xx: fix use-after-free in
device removal path"), but ISCI needs the kill after wait_for_stop().

The Linux kernel CVE team has assigned CVE-2026-64103 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.0 with commit 6f231dda68080759f1aed3769896e94c73099f0f and fixed in 5.10.258 with commit 1412995e10c74644b47f242aea6e4f3d4180e806
	Issue introduced in 3.0 with commit 6f231dda68080759f1aed3769896e94c73099f0f and fixed in 5.15.209 with commit a83d3e4daba40d49324cec1c51ed261e1ea48cf1
	Issue introduced in 3.0 with commit 6f231dda68080759f1aed3769896e94c73099f0f and fixed in 6.1.175 with commit ab2266601a875982f2d2033f41e070a6d5e615e2
	Issue introduced in 3.0 with commit 6f231dda68080759f1aed3769896e94c73099f0f and fixed in 6.6.142 with commit 309c6058622d080fe8c2fab87c30da82d834d989
	Issue introduced in 3.0 with commit 6f231dda68080759f1aed3769896e94c73099f0f and fixed in 6.12.92 with commit cb9e72c50e6c81a5903f27e0b397ce8525d7539b
	Issue introduced in 3.0 with commit 6f231dda68080759f1aed3769896e94c73099f0f and fixed in 6.18.34 with commit b9ff8631006233ba246828ac70409d2cb2da38d3
	Issue introduced in 3.0 with commit 6f231dda68080759f1aed3769896e94c73099f0f and fixed in 7.0.11 with commit 6d40f2f103bb30f52f3dbadbe2c3fdf274a9763c
	Issue introduced in 3.0 with commit 6f231dda68080759f1aed3769896e94c73099f0f and fixed in 7.1 with commit b52a8d52c3125ec9a93106ed816582368de34426

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64103
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/scsi/isci/host.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/1412995e10c74644b47f242aea6e4f3d4180e806
	https://git.kernel.org/stable/c/a83d3e4daba40d49324cec1c51ed261e1ea48cf1
	https://git.kernel.org/stable/c/ab2266601a875982f2d2033f41e070a6d5e615e2
	https://git.kernel.org/stable/c/309c6058622d080fe8c2fab87c30da82d834d989
	https://git.kernel.org/stable/c/cb9e72c50e6c81a5903f27e0b397ce8525d7539b
	https://git.kernel.org/stable/c/b9ff8631006233ba246828ac70409d2cb2da38d3
	https://git.kernel.org/stable/c/6d40f2f103bb30f52f3dbadbe2c3fdf274a9763c
	https://git.kernel.org/stable/c/b52a8d52c3125ec9a93106ed816582368de34426

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-07-19 15:43 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-19 15:39 CVE-2026-64103: scsi: isci: Fix use-after-free in device removal path Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.