Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition

qla24xx_report_id_acquisition() format-1 handling drops vport_slock after
taking the vport reference and then calls qla_update_host_map() without
the lock. That reaches qla_update_vp_map(), which mutates the ha->host_map
btree via btree_insert32()/btree_update32()/btree_remove32() and is
documented to require vport_slock to be held by the caller. Running it
unlocked can race concurrent host_map updates and corrupt the btree.

The format-2 path in the same function already wraps its host_map update
(SET_AL_PA) in vport_slock; the format-1 path is the lone outlier.

Hold vport_slock across the format-1 qla_update_host_map() call to honor
the documented locking contract. The vref_count taken in the loop keeps
the vport valid, so this only adds the missing host_map serialization.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s qla2xxx SCSI driver contains a race condition in the report‑ID acquisition path for format‑1. The code drops an essential lock before updating a B‑tree that manages host maps, violating the documented locking contract. Concurrent updates can corrupt the tree, causing kernel panics, crashes, or driver instability. This leads to denial of service at the kernel level.

Affected Systems

All Linux kernel builds that include the vulnerable qla2xxx SCSI driver, particularly those using QLogic QLA2XXX adapters, are affected. The vulnerability is specific to the Linux kernel’s qla2xxx driver code and the associated host map B‑tree structures.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the EPSS score of <1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would need local or privileged access to send SCSI commands that trigger the format‑1 path, which can lead to a kernel crash and service denial. The likely attack vector is a local or privileged threat actor leveraging SCSI commands to induce the race condition, potentially causing a denial of service.

Generated by OpenCVE AI on September 18, 2026 at 09:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the qla2xxx driver patch addressing the missing lock during host‑map updates.
  • If an upgrade is not immediately possible, unload or blacklist the qla2xxx driver to prevent execution of the vulnerable code.
  • Apply an in‑kernel patch that reintroduces vport_slock around the qla_update_host_map call to temporarily restore proper synchronization.
  • Monitor system logs for indications of B‑tree corruption or kernel crashes associated with the qla2xxx driver.

Generated by OpenCVE AI on September 18, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition qla24xx_report_id_acquisition() format-1 handling drops vport_slock after taking the vport reference and then calls qla_update_host_map() without the lock. That reaches qla_update_vp_map(), which mutates the ha->host_map btree via btree_insert32()/btree_update32()/btree_remove32() and is documented to require vport_slock to be held by the caller. Running it unlocked can race concurrent host_map updates and corrupt the btree. The format-2 path in the same function already wraps its host_map update (SET_AL_PA) in vport_slock; the format-1 path is the lone outlier. Hold vport_slock across the format-1 qla_update_host_map() call to honor the documented locking contract. The vref_count taken in the loop keeps the vport valid, so this only adds the missing host_map serialization.
Title scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:13.254Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89844

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:51.567

Modified: 2026-09-16T15:18:12.703

Link: CVE-2026-89844

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:00:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')