CVE-2026-97527
8.8 HIGHPublished 2026-09-25 · Updated 2026-09-25
AI risk analysis
- Summary
- This vulnerability arises from the lack of proper synchronization in the scsi: qla2xxx driver, leading to potential corruption of the unsol_ctx_head list. It matters because concurrent modifications can cause data races and system instability.
- Exploitability
- Exploitation requires access to the affected SCSI device and concurrent operations on the unsol_ctx_head list. It is moderately difficult to exploit due to the need for specific timing and access conditions.
- Blast radius
- If exploited, the vulnerability could lead to denial of service (DoS) conditions or potential data corruption affecting the storage subsystem.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the specific version 5.10.103 or later, as published in the advisory.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock The fcport->unsol_ctx_head list is modified from several contexts without a common lock. Entries are added in qla2xxx_process_purls_iocb() from the response queue ISR (under the qpair qp_lock), while they are removed from qla2xxx_process_purls_pkt() (DPC/purex worker), qla_nvme_xmt_ls_rsp() (NVMe-FC transport callback) and qla_nvme_release_lsrsp_cmd_kref() (SRB completion). The qpair qp_lock cannot serialize this per-fcport list since multiqueue adapters add entries through different qpairs, so a concurrent add and delete (or two concurrent deletes) can corrupt the list pointers. Introduce a dedicated per-fcport spinlock, unsol_ctx_lock, initialized in qla2x00_alloc_fcport(), and take it around every list_add_tail()/list_del() on unsol_ctx_head. The add nests under the existing qp_lock; no delete path takes qp_lock, so the lock order is consistent and deadlock free.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-100075
- HIGHCVE-2026-64562
- CRITICALCVE-2026-64564
- HIGHCVE-2026-64575
- HIGHCVE-2026-64577
- HIGHCVE-2026-64580
- HIGHCVE-2026-64581
- HIGHCVE-2026-89774
Related by shared AI tags and CWE weakness class. Browse the full archive.