8.8

CVE-2026-97528

scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error

qla_nvme_xmt_ls_rsp() obtains uctx, which was linked into
fcport->unsol_ctx_head by qla2xxx_process_purls_iocb() and is still linked
when the NVMe transport calls back to transmit the LS response. On the
error (out:) path the function frees uctx with kfree() but never removes
it from the list. This leaves a freed node in fcport->unsol_ctx_head: the
next list_add_tail() for that fcport writes through the freed node, and a
subsequent list_del() can corrupt the list or panic.

Unlink uctx with list_del() before kfree() on the error path, matching the
other free sites in qla_nvme_release_lsrsp_cmd_kref() and
qla2xxx_process_purls_pkt(). qla2x00_rel_sp() in the failure path only
returns the SRB to its pool and does not invoke sp->put_fn, so the out:
path is the sole free and uctx is always still linked there.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < cbbf1484496aac86038e67ac984949af58009d4b
Status affected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < a95fc5f1c12bba1dbff72bd2611e7fad0758831b
Status affected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < c55d649a6cc246c3ccd5d118faea230c46b60f35
Status affected
Version 875386b98857822b77ac7f95bdf367b70af5b78c
Version < e46160a5d4fa59bf4d5f3412b6b5cb79edb967dd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.222
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a95fc5f1c12bba1dbff72bd2611e7fad0758831b
https://git.kernel.org/stable/c/c55d649a6cc246c3ccd5d118faea230c46b60f35
https://git.kernel.org/stable/c/e46160a5d4fa59bf4d5f3412b6b5cb79edb967dd
https://git.kernel.org/stable/c/cbbf1484496aac86038e67ac984949af58009d4b