CVE-2026-89849
- EPSS 0.35%
- Veröffentlicht 16.09.2026 10:31:23
- Zuletzt bearbeitet 16.09.2026 15:18:13
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path qla2x00_status_entry() filters out non-TYPE_SRB entries and the SRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then fa...
CVE-2026-89848
- EPSS 0.51%
- Veröffentlicht 16.09.2026 10:31:22
- Zuletzt bearbeitet 16.09.2026 15:18:13
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Quiesce response IRQ before freeing request queue qla2xxx_delete_qpair() deletes the request queue before the response queue. qla25xx_delete_req_que() frees the requ...
CVE-2026-89847
- EPSS 0.68%
- Veröffentlicht 16.09.2026 10:31:21
- Zuletzt bearbeitet 16.09.2026 15:18:12
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOCB timeout qla2x00_async_iocb_timeout() tries to abort a timed-out async IOCB. When qla24xx_async_abort_cmd() fails, both the SRB_...
CVE-2026-89846
- EPSS 0.7%
- Veröffentlicht 16.09.2026 10:31:20
- Zuletzt bearbeitet 16.09.2026 15:18:12
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: if (...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:31:19
- Zuletzt bearbeitet 16.09.2026 11:16:51
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() qla2x00_error_entry() reads ha->req_q_map[que] twice: once for the NULL check and again when assigning it to req...
CVE-2026-89844
- EPSS 0.34%
- Veröffentlicht 16.09.2026 10:31:18
- Zuletzt bearbeitet 16.09.2026 15:18:12
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition qla24xx_report_id_acquisition() format-1 handling drops vport_slock after taking the vport reference an...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:31:17
- Zuletzt bearbeitet 16.09.2026 11:16:51
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak Several bsg handlers stage their request/reply in an uninitialized 256-byte on-stack buffer (uint8_t bsg[DMA_POOL_SIZE...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:31:16
- Zuletzt bearbeitet 16.09.2026 11:16:51
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started qla_nvme_xmt_ls_rsp() bails out to the out: label when firmware is not started (!ha->flags.fw_started), but the out: pat...
CVE-2026-89840
- EPSS 0.14%
- Veröffentlicht 16.09.2026 10:31:14
- Zuletzt bearbeitet 03.10.2026 11:17:44
In the Linux kernel, the following vulnerability has been resolved: f2fs: validate MOVE_RANGE destination size F2FS_IOC_MOVE_RANGE checks the source range, but not the destination end before updating i_size. A source hole can expose this: __clone_b...
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:31:13
- Zuletzt bearbeitet 16.09.2026 11:16:50
In the Linux kernel, the following vulnerability has been resolved: f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() f2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing the "system.advi...