{"apiVersion":"1.0","identifier":"CVE-2026-72086","description":"In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free the command tag on the TMR submit-failure path scsiback_device_action() obtains a command tag in scsiback_get_pend_req() and submits a task-management request with target_submit_tmr(). When target_submit_tmr() fails it returns < 0 and scsiback jumps to the err: label, which sends a response but frees nothing, leaking the tag. Impact: a pvSCSI guest can leak the command tags of a LUN-s session, stopping the LUN, by issuing VSCSIIF_ACT_SCSI_ABORT or RESET requests whenever target_submit_tmr() fails. transport_generic_free_cmd() cannot be used here. By the time target_submit_tmr() returns an error it has already run __target_init_cmd() (so se_cmd->cmd_kref is one, not zero), and on its target_get_sess_cmd() error path it has freed se_cmd->se_tmr_req via core_tmr_release_req() while leaving SCF_SCSI_TMR_CDB set and the pointer dangling. Letting the command release run target_free_cmd_mem() would then double-free se_tmr_req. Use the same helper, which returns just the tag, on this path too.","publishedAt":"2026-08-15T06:21:22","lastModifiedAt":"2026-08-17T06:18:07","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72086","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00206,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72086","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72086","en":"https://www.redsauce.net/en/cves/CVE-2026-72086","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72086","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72086","de":"https://www.redsauce.net/de/cves/CVE-2026-72086","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72086","el":"https://www.redsauce.net/el/cves/CVE-2026-72086"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72086"}}