-

CVE-2026-97530

scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature

qla27xx_copy_multiple_pkt() and qla27xx_copy_fpin_pkt() poll
rsp_q->ring_ptr->signature for RESPONSE_PROCESSED (0xDEADDEAD) to decide
whether the next continuation IOCB has arrived, spinning on cpu_relax()
without advancing the ring or decrementing the entry count while it has
not. response_t::signature lives at byte offset 60, but a continuation
IOCB (sts_cont_entry_t / struct sts_cont_entry_ext) carries raw FC frame
payload at that offset (data[56..59]). A received frame whose payload
bytes happen to equal 0xDEADDEAD is therefore misread as "not yet
arrived", and the loop spins forever in interrupt/DPC context, causing a
CPU soft lockup.

The poll is also unnecessary: callers of qla27xx_copy_multiple_pkt()
(PT_LS4_UNSOL and the NVMe purls path) already gate on
qla_chk_cont_iocb_avail(), which guarantees all entry_count IOCBs are
present before copying begins. The sibling helper
__qla_copy_purex_to_buffer() already drops the signature poll and relies
on the entry_type == STATUS_CONT_TYPE guard instead.

Remove the signature busy-wait from both helpers, keeping the entry_type
guard, and gate the FPIN path with qla_chk_cont_iocb_avail() so it defers
and re-processes on the next interrupt once all continuation IOCBs have
arrived, mirroring the ELS_AUTH_ELS and PT_LS4_UNSOL arms. With this the
signature field is never read on a continuation IOCB, eliminating the
payload-aliasing lockup.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9f2475fe7406b8ef5f97099c4980021344872d9f
Version < 3e58eb888ebf265af937f636d05997c60d2f197c
Status affected
Version 9f2475fe7406b8ef5f97099c4980021344872d9f
Version < 6e6c2ba9022eb8f9b062c81bdc6fd24c7b4c4c16
Status affected
Version 9f2475fe7406b8ef5f97099c4980021344872d9f
Version < 6aa722fca9d2aa1f64094101587f8f4a2f83f6aa
Status affected
Version 9f2475fe7406b8ef5f97099c4980021344872d9f
Version < d7e3fa7d06bf7fcaac186d3c4d635caac166d36c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.9
Status affected
Version 0
Version < 5.9
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.086
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6e6c2ba9022eb8f9b062c81bdc6fd24c7b4c4c16
https://git.kernel.org/stable/c/6aa722fca9d2aa1f64094101587f8f4a2f83f6aa
https://git.kernel.org/stable/c/d7e3fa7d06bf7fcaac186d3c4d635caac166d36c
https://git.kernel.org/stable/c/3e58eb888ebf265af937f636d05997c60d2f197c