CVE-2026-68396 is a vulnerability in Linux Kernel
Published on August 10, 2026
scsi: core: wake eh reliably when using scsi_schedule_eh
In the Linux kernel, the following vulnerability has been resolved:
scsi: core: wake eh reliably when using scsi_schedule_eh
Drivers which use the scsi_schedule_eh function to run the error handler
currently risk the error handler thread never waking once all commands are
timed out or inactive. There is no enforced memory order between setting
the host into error recovery state and counting busy commands. This can
result in a race with scsi_dec_host_busy where neither CPU sees both
conditions of all commands inactive and the host error state to request
waking the error handler.
To fix this, run the scsi_schedule_eh's scsi_eh_wakeup from a new work item
which will use rcu to ensure scsi_schedule_eh's call to scsi_host_busy will
occur after the error state is globally visible and will be seen by any
current scsi_dec_host_busy callers.
Products Associated with CVE-2026-68396
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 6eb045e092efefafc6687409a6fa6d1dabf0fb69 and below 866efe8ae8b8b4d095501001b026e1022734be28 is affected.
- Version 6eb045e092efefafc6687409a6fa6d1dabf0fb69 and below c7a15091237205770bd9bd4d14eb1f3029d97a34 is affected.
- Version 6eb045e092efefafc6687409a6fa6d1dabf0fb69 and below 24d7abda6a2a19e113334accc10029f6a4b57257 is affected.
- Version 6eb045e092efefafc6687409a6fa6d1dabf0fb69 and below dccf3b1798b70f94e958b3d00b83010399e6fb05 is affected.
- Version 5.5 is affected.
- Before 5.5 is unaffected.
- Version 6.12.101, <= 6.12.* is unaffected.
- Version 6.18.42, <= 6.18.* is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc4, <= * is unaffected.