Junglewise Threat Intelligence

CVE-2026-63889: Linux Kernel infinite loop in scsi_transport_fc FPIN processing

CVE-2026-63889 · Severity: info · CVSS 6.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Fibre Channel transport layer could allow an attacker on the same storage network to cause a system hang or denial-of-service. By sending specially crafted management frames, a compromised switch or storage device can trigger an infinite loop in the kernel. This would result in the affected server becoming unresponsive, potentially disrupting access to critical data and storage operations.

Technical details

An infinite loop vulnerability exists in the Linux kernel's scsi_transport_fc component due to an integer truncation/wrap-around. The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop counter to iterate over a 32-bit on-wire 'pname_count' field. If an attacker provides a 'pname_count' of 256 or greater, the u8 counter wraps back to zero, causing the loop condition to remain true indefinitely. This can be triggered by an adjacent Fibre Channel fabric actor (e.g., a compromised switch or a spoofed N_Port) delivering a malicious FPIN ELS frame to an lpfc or qla2xxx initiator. The fix involves widening the counter to u32 and clamping the count against the validated descriptor body size.

Affected products

  • Linux Linux Kernel 5.11 to 7.1.y (fixed in various stable branches)

Timeline

  • 2026-05-20: other: Vulnerability reported and patch authored
  • 2026-06-19: patched: Patch committed to stable trees
  • 2026-07-19: disclosed: CVE-2026-63889 published

References

Related threats