Back

HIGH

scsi: aic94xx: fix use-after-free in device removal path

Published Jan 13, 2026

Description

The asd_pci_remove() function fails to synchronize with pending tasklets before freeing the asd_ha structure, leading to a potential use-after-free vulnerability.

When a device removal is triggered (via hot-unplug or module unload), race condition can occur.

The fix adds tasklet_kill() before freeing the asd_ha structure, ensuring all scheduled tasklets complete before cleanup proceeds.

Affected products

Remediation

Red Hat statement

This can be triggered during PCI hot-unplug or module unload of the aic94xx driver. Systems with Adaptec AIC-94xx SAS controllers are affected. The fix adds tasklet_kill() to ensure proper synchronization before cleanup.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jan 13, 2026
Updated Sep 8, 2026
Reserved Jan 13, 2026
CISA Vulnrichment
Updated Jun 10, 2026
NVD
Status Modified
Modified Jul 14, 2026
Red Hat
Severity Low
Public date Jan 13, 2026