9.8

CVE-2026-89857

scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject

qla_nvme_ls_reject_iocb() allocates from and advances the request ring
through __qla2x00_alloc_iocbs() (which assumes the hardware_lock is
held) and qla2x00_start_iocbs() (which advances the ring and rings the
request-in doorbell), but takes no lock itself. Two of its callers
invoke it without the producer lock held:

 - qla_nvme_xmt_ls_rsp(), the NVMe-FC .xmt_ls_rsp transport callback, on
   its error path, and

 - qla2xxx_process_purls_pkt(), run from the purex work/DPC context.

Both use ha->base_qpair, whose qp_lock_ptr is hardware_lock, so they can
run concurrently with normal I/O submission on the base ring and corrupt
the ring producer state, leading to duplicated or dropped commands. The
third caller, qla2xxx_process_purls_iocb(), runs inside
qla24xx_process_response_queue() with the qpair lock already held and is
safe; that is also why the lock cannot be taken inside the helper itself
(it would recursively re-acquire hardware_lock on the response path).

Take qp_lock_ptr around the two unlocked callers and document the helper
as caller-locked. Both run in process context, so spin_lock_irqsave() is
used and nothing in the locked region sleeps.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < 7eb618877503edbf17aa65e357a81bda1fc8f163
Status affected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < b3a362466db6b8ec47cc537ac641ac197fa69b5d
Status affected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < 11834e5773e20fd3742d7eb900876e66b9e7d029
Status affected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < b02ff132017b28222187ebcf95ce7f4cb576cd36
Status affected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < f743488e4a203049f27ec5d8cd0caccc483af01e
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.482
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7eb618877503edbf17aa65e357a81bda1fc8f163
https://git.kernel.org/stable/c/b3a362466db6b8ec47cc537ac641ac197fa69b5d
https://git.kernel.org/stable/c/11834e5773e20fd3742d7eb900876e66b9e7d029
https://git.kernel.org/stable/c/b02ff132017b28222187ebcf95ce7f4cb576cd36
https://git.kernel.org/stable/c/f743488e4a203049f27ec5d8cd0caccc483af01e