8.4

CVE-2026-89856

scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation

ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and
ha->max_qpairs are u8. Deriving the queue count as
"ha->max_req_queues = ha->msix_count - 1" therefore truncates: a board
(or a misconfigured/malicious hot-plugged device) advertising 257 MSI-X
vectors yields msix_count - 1 == 256, which truncates to 0. An MSI-X
count of 1 zeroes it as well, and in target mode the subsequent
"ha->max_req_queues--" then underflows 0 to 255.

When the count is 0, qla2x00_alloc_queues() calls
kzalloc_objs(struct req_que *, 0), which returns ZERO_SIZE_PTR. That is
not NULL, so the allocation check passes and the following
"ha->req_q_map[0] = req" dereferences ZERO_SIZE_PTR, corrupting memory
or crashing the kernel.

Add qla_calc_queue_count() to clamp the derived value into
[1, QLA_MAX_QUEUES - 1] so it always fits in u8 and is never zero, and
use it at all three derivation sites (qla25xx_iospace_config(),
qla83xx_iospace_config() and qla24xx_enable_msix()). Also guard the
target-mode decrement so it cannot reintroduce a zero (which would in
turn underflow max_qpairs).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d74595278f4ab192af66d9e60a9087464638beee
Version < cf623d32761b00f221a9cfded3303d56e84b429d
Status affected
Version d74595278f4ab192af66d9e60a9087464638beee
Version < 9eeddbeaa896f39d943644b16d83a6ad0ceab255
Status affected
Version d74595278f4ab192af66d9e60a9087464638beee
Version < 802068b9b683b8008fcccbf6e9ad133e597ec87c
Status affected
Version d74595278f4ab192af66d9e60a9087464638beee
Version < e80adfeac61b4d5db7ffe0f5af43999c33a4145e
Status affected
Version d74595278f4ab192af66d9e60a9087464638beee
Version < 2efe50b2da829909023de4a2eb87badb7cfa53cc
Status affected
Version d74595278f4ab192af66d9e60a9087464638beee
Version < 7a448f5ed0b283dbde4e9183dd1e98c221432dab
Status affected
Version d74595278f4ab192af66d9e60a9087464638beee
Version < 33c77254e6e91f37c72c7fad4051777452b10de8
Status affected
Version d74595278f4ab192af66d9e60a9087464638beee
Version < ebfd35c64433821bd5619a6d07ccc2df8b5b1de3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.10
Status affected
Version 0
Version < 4.10
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.081
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cf623d32761b00f221a9cfded3303d56e84b429d
https://git.kernel.org/stable/c/9eeddbeaa896f39d943644b16d83a6ad0ceab255
https://git.kernel.org/stable/c/802068b9b683b8008fcccbf6e9ad133e597ec87c
https://git.kernel.org/stable/c/e80adfeac61b4d5db7ffe0f5af43999c33a4145e
https://git.kernel.org/stable/c/2efe50b2da829909023de4a2eb87badb7cfa53cc
https://git.kernel.org/stable/c/7a448f5ed0b283dbde4e9183dd1e98c221432dab
https://git.kernel.org/stable/c/33c77254e6e91f37c72c7fad4051777452b10de8
https://git.kernel.org/stable/c/ebfd35c64433821bd5619a6d07ccc2df8b5b1de3