CVE-2026-89514EPSS p9.8%
CVE-2026-89514CVE-2026-89514
Description
In the Linux kernel, the following vulnerability has been resolved:
scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
fnic_fcoe_process_vlan_resp() allocates a VLAN descriptor with
kzalloc_obj() (default GFP_KERNEL) while holding vlans_lock via
spin_lock_irqsave(). GFP_KERNEL may sleep, which is not allowed in this
atomic context and can trigger a sleeping-from-invalid-context warning
or deadlock.
Pass GFP_ATOMIC so the allocation is safe under the IRQ-safe spinlock.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 9.8% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-11 |