CVE-2026-80653

Source
https://cve.org/CVERecord?id=CVE-2026-80653
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80653.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80653
Downstream
Published
2026-08-28T06:49:00.717Z
Modified
2026-08-30T03:47:21.705493296Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
scsi: hisi_sas: Add slave_destroy interface for v3 hw
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: hisisas: Add slavedestroy interface for v3 hw

WARNING is triggered when executing link reset of remote PHY and rmmod SAS driver simultaneously. Following is the WARNING log:

WARNING: CPU: 61 PID: 21818 at drivers/base/core.c:1347 __devicelinksno_driver+0xb4/0xc0 Call trace: __devicelinksnodriver+0xb4/0xc0 devicelinksdrivercleanup+0xb0/0xfc __devicereleasedriver+0x198/0x23c devicereleasedriver+0x38/0x50 busremovedevice+0x130/0x140 device_del+0x184/0x434 _scsiremovedevice+0x118/0x150 scsiremovetarget+0x1bc/0x240 sasrphyremove+0x90/0x94 sasrphydelete+0x24/0x3c sasdestructdevices+0x64/0xa0 [libsas] sasrevalidatedomain+0xe4/0x150 [libsas] processonework+0x1e0/0x46c workerthread+0x15c/0x464 kthread+0x160/0x170 retfromfork+0x10/0x20 ---[ end trace 71e059eb58f85d4a ]---

During SAS phy up, link->status is set to DLSTATEAVAILABLE in devicelinksdriver_bound, then this setting influences _devicelinksnodriver() before driver rmmod and caused WARNING.

Add the slave_destroy interface to make sure link is removed after flush workque.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80653.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
16fd4a7c5917097e9a3da03b39a92381eee40724
Fixed
cb414aff28e18e6f5cff9f87ea31376ed8af317b
Fixed
4867dba229292e13fc19ed865ec1839661952ff9
Fixed
67b85a88265df19f049241d8c00571a5408f4eeb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80653.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80653.json"