PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72086 Linux CVE debrief

The Linux kernel has a vulnerability in the scsi: xen: scsiback module. When a task-management request submission fails, the command tag is not freed, potentially leading to a leak of command tags for a LUN's session. This issue can be triggered by a pvSCSI guest issuing VSCSIIF_ACT_SCSI_ABORT or RESET requests. The vulnerability has been resolved by freeing the command tag on the TMR submit-failure path. Affected systems should be inventoried and patched, with compensating controls implemented to mitigate potential exploitation. Monitoring for exploitation attempts is also recommended.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

System administrators and security teams responsible for Linux kernel-based systems, particularly those using pvSCSI guests, should be aware of this vulnerability and take necessary actions to mitigate it. This includes inventorying affected systems, applying patches, and implementing compensating controls. Security teams should also monitor for potential exploitation attempts and review system logs for suspicious activity. Additionally, operators of affected platforms and vulnerability management teams should prioritize patching and review their security controls to ensure they are adequate to protect against this vulnerability. Those responsible for change management and incident response should also be aware of the potential impact of this vulnerability and have plans in place to respond quickly in case of an exploit. The vulnerability management process should be updated to include checks for this vulnerability, and asset owners should be notified of the potential risk. Security teams should also review their monitoring and detection capabilities to ensure they can detect potential exploitation attempts. The incident response plan should be updated to include procedures for responding to an exploit of this vulnerability. Those responsible for source tracking and vulnerability management should also review their processes to ensure they are adequate to detect and respond to this vulnerability. Compensating controls, such as additional monitoring or restrictions on access, may be necessary for systems that cannot be patched immediately. The vulnerability should be prioritized based on its potential impact and the likelihood of exploitation. Those responsible for Linux kernel-based systems should review their systems for potential exposure and take necessary actions to mitigate the vulnerability. The vulnerability should be addressed through a coordinated effort between system administrators, security teams, and vulnerability management teams. Those responsible for security awareness and training should also be notified of the vulnerability and its potential impact, so they can provide guidance to system administrators and users on how to mitigate it. The patch

Technical summary

The vulnerability is in the scsiback_device_action() function, which obtains a command tag and submits a task-management request. If the submission fails, the function jumps to the err: label, which sends a response but does not free the tag. This can lead to a leak of command tags for a LUN's session. The issue has been resolved by freeing the command tag on the TMR submit-failure path. System administrators and security teams should review the vulnerability and implement necessary mitigations.

Defensive priority

Medium

Recommended defensive actions

  • Inventory affected systems and apply the patch
  • Monitor for potential exploitation attempts
  • Implement compensating controls to mitigate the vulnerability
  • Review system logs for suspicious activity
  • Verify patch deployment and system security
  • Update incident response plans to include procedures for responding to an exploit
  • Notify asset owners of the potential risk and necessary actions

Evidence notes

The vulnerability is caused by a failure to free the command tag when a task-management request submission fails. The issue is in the scsiback_device_action() function, which obtains a command tag and submits a task-management request. If the submission fails, the function jumps to the err: label, which sends a response but does not free the tag. This can lead to a leak of command tags for a LUN's session.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72086 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72086

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72086 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72086

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1357fb32d42ad8da193e6da285f09e6452feabda

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/18d4f86816592586b38513543b5e1f9553bc271f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/255fb7b0cdc947b1c01929c7f133281342a3a6b5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4567ce79fe2f84c3dcc3a91b22a377cf482d33ad

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/66aefc277ebb796ec285d550305535dc3fc0179f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6c01f0439098f00a64b246dc27479602201382f7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fbc1bdede66d0f2cde83b75d6524ce1a815bb69f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.