← Back to search

CVE-2026-97527

8.8 HIGH

Published 2026-09-25 · Updated 2026-09-25

AI risk analysis

Summary
This vulnerability arises from the lack of proper synchronization in the scsi: qla2xxx driver, leading to potential corruption of the unsol_ctx_head list. It matters because concurrent modifications can cause data races and system instability.
Exploitability
Exploitation requires access to the affected SCSI device and concurrent operations on the unsol_ctx_head list. It is moderately difficult to exploit due to the need for specific timing and access conditions.
Blast radius
If exploited, the vulnerability could lead to denial of service (DoS) conditions or potential data corruption affecting the storage subsystem.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the specific version 5.10.103 or later, as published in the advisory.
dosstoragekernel

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock The fcport->unsol_ctx_head list is modified from several contexts without a common lock. Entries are added in qla2xxx_process_purls_iocb() from the response queue ISR (under the qpair qp_lock), while they are removed from qla2xxx_process_purls_pkt() (DPC/purex worker), qla_nvme_xmt_ls_rsp() (NVMe-FC transport callback) and qla_nvme_release_lsrsp_cmd_kref() (SRB completion). The qpair qp_lock cannot serialize this per-fcport list since multiqueue adapters add entries through different qpairs, so a concurrent add and delete (or two concurrent deletes) can corrupt the list pointers. Introduce a dedicated per-fcport spinlock, unsol_ctx_lock, initialized in qla2x00_alloc_fcport(), and take it around every list_add_tail()/list_del() on unsol_ctx_head. The add nests under the existing qp_lock; no delete path takes qp_lock, so the lock order is consistent and deadlock free.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.