8.8

CVE-2026-89849

scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path

qla2x00_status_entry() filters out non-TYPE_SRB entries and the
SRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a
SCSI fast path that assumes the command is an SRB_SCSI_CMD. The first
thing on that path, qla_chk_edif_rx_sa_delete_pending(), and the
subsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd.

The srb u union overlays the SCSI command pointer with other command
layouts (bsg_job, iocb_cmd). If firmware delivers an unexpected
STATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a
non-NULL garbage pointer, bypassing the NULL checks in
qla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and
leading to a wild pointer dereference.

Reject any SRB whose type is not SRB_SCSI_CMD before entering the fast
path. The outstanding_cmds slot is left untouched so a genuinely
non-SCSI command still completes through its proper handler.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version dd30706e73b70d67e88fdaca688db7a3374fd5de
Version < 9204fb0888374083be74f799049649a17eab4191
Status affected
Version dd30706e73b70d67e88fdaca688db7a3374fd5de
Version < b7418198b45b327194b97f856fe8ea8daa91f3fd
Status affected
Version dd30706e73b70d67e88fdaca688db7a3374fd5de
Version < 8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6
Status affected
Version dd30706e73b70d67e88fdaca688db7a3374fd5de
Version < e38041b47c29316ba79b645e2ae0b713d216b1db
Status affected
Version dd30706e73b70d67e88fdaca688db7a3374fd5de
Version < e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805
Status affected
Version dd30706e73b70d67e88fdaca688db7a3374fd5de
Version < 29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9
Status affected
Version dd30706e73b70d67e88fdaca688db7a3374fd5de
Version < 0f41d07d72f2245208c45374ca8d0a1846cad667
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.291
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9204fb0888374083be74f799049649a17eab4191
https://git.kernel.org/stable/c/b7418198b45b327194b97f856fe8ea8daa91f3fd
https://git.kernel.org/stable/c/8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6
https://git.kernel.org/stable/c/e38041b47c29316ba79b645e2ae0b713d216b1db
https://git.kernel.org/stable/c/e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805
https://git.kernel.org/stable/c/29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9
https://git.kernel.org/stable/c/0f41d07d72f2245208c45374ca8d0a1846cad667