7.5

CVE-2026-97531

scsi: qla2xxx: Skip vport under deletion in report ID acquisition

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Skip vport under deletion in report ID acquisition

qla24xx_report_id_acquisition() format-1 handling walks ha->vp_list under
vport_slock, takes a vref_count on the matching vport and calls
qla_update_host_map() to register its port id.

A vport teardown via qla24xx_vport_delete() sets VPORT_DELETE, then
qla24xx_disable_vp() removes the vport from the host_map btree and zeroes
vha->d_id (RESET_AL_PA). The vport is only unlinked from vp_list later,
in qla24xx_deallocate_vp_id(), which clears vp_map[idx] (RESET_VP_IDX)
but does not touch host_map. In the window in between, report ID
acquisition can still find the vport on vp_list and call
qla_update_host_map(); with d_id already zeroed it takes the
btree_insert32() path and re-inserts the dying vport into host_map.
Nothing cleans that entry afterwards, so once scsi_host_put() frees the
vha a later host_map lookup dereferences freed memory.

Skip a vport that has VPORT_DELETE set before taking the reference, so it
is neither re-registered nor scheduled for DPC re-registration. This
mirrors the existing guard in qla2x00_alert_all_vps().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 41dc529a4602ac737020f423f84686a81de38e6d
Version < 20bb54601d2655e83795b73499c89f6b1cb31016
Status affected
Version 41dc529a4602ac737020f423f84686a81de38e6d
Version < d61e8de98c5a52978fb1edd95fe4dde3131b280e
Status affected
Version 41dc529a4602ac737020f423f84686a81de38e6d
Version < 7a83979d92782f83c90888ebe19bdc9420521940
Status affected
Version 41dc529a4602ac737020f423f84686a81de38e6d
Version < 23582731afa35031c94fadb71a4f3b4afd094649
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.11
Status affected
Version 0
Version < 4.11
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.179
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 1.6 5.9
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d61e8de98c5a52978fb1edd95fe4dde3131b280e
https://git.kernel.org/stable/c/7a83979d92782f83c90888ebe19bdc9420521940
https://git.kernel.org/stable/c/23582731afa35031c94fadb71a4f3b4afd094649
https://git.kernel.org/stable/c/20bb54601d2655e83795b73499c89f6b1cb31016