SCSI Device Management Vulnerability in Linux Kernel Affecting Multiple Vendors
CVE-2026-74555
What is CVE-2026-74555?
A vulnerability in the Linux kernel's SCSI management functionality can lead to a deadlock scenario during the HA resume process. Specifically, this occurs when the PHYE_RESUME_TIMEOUT handler interacts with device management functions, causing the host to wait indefinitely while the device attempts to become active again. Consequently, this results in devices being disabled if commands are sent to a suspended controller. Recent changes address this issue by reordering the notification process associated with device management, ensuring that operations complete successfully without causing further deadlocks or race conditions.
Affected Version(s)
Linux fbefe22811c3140a686e407e114789ebf328a9a2
Linux fbefe22811c3140a686e407e114789ebf328a9a2
Linux fbefe22811c3140a686e407e114789ebf328a9a2 < 9e24b47ef81d43b3fb1b14294f09991640c79fcc