-

CVE-2026-97535

scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size

The VP control IOCB selects its target virtual port by setting one bit
in vp_idx_map, a fixed 16-byte (128-bit) array in both
vp_ctrl_entry_24xx and vp_ctrl_entry_24xx_ext. qla25xx_ctrlvp_iocb()
computes map = (vp_index - 1) / 8 and writes vce->vp_idx_map[map]
without checking that map stays within the array.

max_npiv_vports is taken from firmware and only sanitized to a
MIN_MULTI_ID_FABRIC-aligned boundary, so it can legitimately be 191 or
255, and qla24xx_control_vp() only rejects vp_index >= max_npiv_vports.
A vp_index above 128 therefore yields map >= 16 and an out-of-bounds
write of up to 16 bytes past vp_idx_map, corrupting the trailing IOCB
fields (or the adjacent request-ring slot on the 64-byte layout).

Reject a vp_index that cannot be represented in the IOCB bitmap in
qla24xx_control_vp(), and add a defensive ARRAY_SIZE() guard in
qla25xx_ctrlvp_iocb() before the write. Adapters that report the usual
63 or 127 NPIV vports are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 2853192e154b813fe34a6cbee5e34dfef50d29d0
Version < c80a0362a0fe548c15a0324b1f61c04b62bb2174
Status affected
Version 2853192e154b813fe34a6cbee5e34dfef50d29d0
Version < 48a44e19746eaa70320a3c2571dcb345192fca72
Status affected
Version 2853192e154b813fe34a6cbee5e34dfef50d29d0
Version < 13354ad251ab009102597a791bc7c4d2265229e1
Status affected
Version 2853192e154b813fe34a6cbee5e34dfef50d29d0
Version < 878613ecb5a36db26859c4fd83daf9283a334fa2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.16
Status affected
Version 0
Version < 4.16
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.086
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/48a44e19746eaa70320a3c2571dcb345192fca72
https://git.kernel.org/stable/c/13354ad251ab009102597a791bc7c4d2265229e1
https://git.kernel.org/stable/c/878613ecb5a36db26859c4fd83daf9283a334fa2
https://git.kernel.org/stable/c/c80a0362a0fe548c15a0324b1f61c04b62bb2174