← Back to search

CVE-2026-97528

8.8 HIGH

Published 2026-09-25 · Updated 2026-09-25

AI risk analysis

Summary
This flaw in the Linux kernel's qla2xxx driver for the QLogic Fibre Channel HBA allows an attacker to corrupt the unsolicited context list, potentially leading to a denial of service or kernel panic.
Exploitability
Exploitation requires the attacker to trigger an LS reject error on an NVMe device, which is relatively difficult and requires specific conditions to be met.
Blast radius
If exploited, the vulnerability could lead to a denial of service or kernel panic, impacting the stability and availability of the affected system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 10.3.22 or later.
doskernelqla2xxx

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error qla_nvme_xmt_ls_rsp() obtains uctx, which was linked into fcport->unsol_ctx_head by qla2xxx_process_purls_iocb() and is still linked when the NVMe transport calls back to transmit the LS response. On the error (out:) path the function frees uctx with kfree() but never removes it from the list. This leaves a freed node in fcport->unsol_ctx_head: the next list_add_tail() for that fcport writes through the freed node, and a subsequent list_del() can corrupt the list or panic. Unlink uctx with list_del() before kfree() on the error path, matching the other free sites in qla_nvme_release_lsrsp_cmd_kref() and qla2xxx_process_purls_pkt(). qla2x00_rel_sp() in the failure path only returns the SRB to its pool and does not invoke sp->put_fn, so the out: path is the sole free and uctx is always still linked there.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.