CVE-2026-63889
Linux kernel FC transport infinite-loop via crafted FPIN frames causing kernel hang.
Is CVE-2026-63889 being exploited?
Not confirmed. CVE-2026-63889 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.36% probability of exploitation in the next 30 days.
How severe is CVE-2026-63889?
CVE-2026-63889 is rated High with a CVSS score of 8.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63889?
Yes. A fix has been recorded for CVE-2026-63889. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63889 affect?
CVE-2026-63889 affects Linux kernel (scsi_transport_fc), lpfc driver, qla2xxx driver, Fibre Channel SAN initiators. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63889?
Apply Linux kernel security updates for scsi_transport_fc and update lpfc/qla2xxx drivers immediately.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote denial-of-service: crafted FPIN ELS frames can trigger an infinite loop/hang in kernel FC transport, disrupting SCSI/FC I/O and possibly crashing the kernel.
Immediate action required
- affected>= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 and < 07776b7779c9426982c1ad74aad91bd531593790
- affected>= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 and < 29f126f09e34a425b376b3646c89aa7cc18b142c
- affected>= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 and < 163bd704d7515c3df6c2e03bcba93d1db79edbff
- affected>= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 and < ee57b89e5da9fffbe0d26647e4ff0750dacb9943
- affected>= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 and < 35461d23744175a78b6280293892cca357c22793
- affected>= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 and < bdff76dff6ec23d6fe35812fa33e5c4ce2cdb770
- affected>= 3dcfe0de5a9752e646a61f4ce513ac059960c7c3 and < a9a39233ec1fc9f97ea1340a4d09bb7ec2be5153
- affected5.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.