PT-2026-61320 · Linux · Linux Kernel

CVE-2026-64003

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the SCSI core where the scsi run host queues() function fails to process devices in a partially removed state, such as SDEV CANCEL. This occurs because the function relies on the shost for each device() macro, which uses scsi device get() and ignores devices not in a fully active state. Consequently, requeued requests for these devices are not kicked after a SCSI host exits a recovery state, which can cause the device removal process to hang.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64003

Affected Products

Linux Kernel