HomeDefectsLIN1024-30940
Fixed

LIN1024-30940 : Security Advisory - linux - CVE-2026-89514

Created: Oct 6, 2026    Updated: Oct 8, 2026
Resolved Date: Oct 7, 2026
Found In Version: 10.24.33.2
Fix Version: 10.24.33.5
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock  fnic_fcoe_process_vlan_resp() allocates a VLAN descriptor with kzalloc_obj() (default GFP_KERNEL) while holding vlans_lock via spin_lock_irqsave(). GFP_KERNEL may sleep, which is not allowed in this atomic context and can trigger a sleeping-from-invalid-context warning or deadlock.  Pass GFP_ATOMIC so the allocation is safe under the IRQ-safe spinlock.