CVE-2026-72085: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

scsi: xen: scsiback: Free unsubmitted command instead of double-putting it

scsibackgetpendreq() obtains a command tag and returns a vscsibkpend whose embedded secmd has only been memset to 0, so its cmdkref is 0; the secmd is initialised (krefinit() via targetinitcmd()) only later, in scsibackcmdexec(), on the successful VSCSIIFACTSCSICDB path. The two error paths in scsibackdocmdfn() taken before the command is submitted -- a failed scsibackgnttabdatamap() and an unknown ringreq.act -- call transportgenericfreecmd(&pendingreq->secmd, 0), which krefput()s a refcount of 0. That underflows it ("refcountt: underflow; use-after-free") and, as the release function is not run, leaks the command tag.

Impact: a pvSCSI guest can leak every command tag of a LUN's session, stopping the LUN, by submitting requests with a bad grant reference or an unknown request type; under paniconwarn the refcount underflow panics the host.

Add a helper that just returns the tag with targetfreetag() and sends the error response. It frees the tag while the v2p reference still pins the session, and snapshots the response fields beforehand because freeing the tag can let another ring reuse the pendingreq slot.

Affected Software

1 affected component
Linux Linux kernel

Event History

Aug 15, 2026
CVE Published
via MITRE·05:52 AM
Data Sourced
via MITRE·05:52 AM
Description
Data Sourced
via NVD·06:21 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-72085?

The severity of CVE-2026-72085 is assessed as 45, indicating a moderate risk.

2

How do I fix CVE-2026-72085?

To fix CVE-2026-72085, ensure that you update to the patched version of the Linux kernel that addresses this vulnerability.

3

What systems are affected by CVE-2026-72085?

CVE-2026-72085 affects systems running vulnerable versions of the Linux kernel utilizing the scsi: xen subsystem.

4

What are the consequences of CVE-2026-72085?

CVE-2026-72085 could lead to unpredicted behavior due to improper handling of command tags and may potentially allow for exploitation due to use after free conditions.

5

When was CVE-2026-72085 published?

CVE-2026-72085 was published on August 15, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203