Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags

The single-doorbell completion path can call ufshcd_compl_one_cqe() with a
NULL CQE. If no command is associated with the completion tag, the warning
message dereferences the CQE while reporting the error. Avoid that
dereference and include the invalid tag in the warning.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Patch
AI Analysis

Impact

A flaw in the Linux kernel’s UFS SCSI driver causes a null pointer dereference in the completion queue entry handling routine when an invalid tag is encountered. The warning‑logging path references the completion queue entry regardless of its validity, leading to a kernel panic and system shutdown. The weakness is a classic NULL pointer dereference, identified as CWE‑476, and does not provide direct code execution but can be leveraged to cause a denial of service for a local or privileged attacker.

Affected Systems

The vulnerability affects all Linux kernel releases that have not incorporated the fixes from commits 331bda797e6afc143127ce72b1469d73316f49b4 and a769095d1d74ebac2b1474c56bbd29bb0b9ed5a7. No specific version range is listed, so any kernel build lacking these patches is potentially impacted.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low likelihood of widespread exploitation, and the issue is not currently listed in CISA’s KEV catalog. Exploitation requires a malformed UFS command or direct interaction with the driver, which is typically a local or privileged attack vector. If successfully triggered, the crash results in kernel instability, making this a moderate‑to‑high severity denial of service rather than a full remote code execution threat.

Generated by OpenCVE AI on September 19, 2026 at 13:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patches from the referenced commits.
  • Reboot the system so the updated kernel and UFS driver take effect.
  • Verify kernel stability by performing a basic read/write test on a UFS device to ensure no further crashes occur.

Generated by OpenCVE AI on September 19, 2026 at 13:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags The single-doorbell completion path can call ufshcd_compl_one_cqe() with a NULL CQE. If no command is associated with the completion tag, the warning message dereferences the CQE while reporting the error. Avoid that dereference and include the invalid tag in the warning.
Title scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:57.058Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:49.950

Modified: 2026-09-17T17:17:49.950

Link: CVE-2026-92479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses