Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Avoid double completion in async IOCB timeout

qla2x00_async_iocb_timeout() tries to abort a timed-out async IOCB. When
qla24xx_async_abort_cmd() fails, both the SRB_LOGIN_CMD path and the
SRB_CTRL_VP/default path scan outstanding_cmds[] for the SRB and then
call sp->done(sp, QLA_FUNCTION_TIMEOUT) unconditionally, without checking
whether the SRB was actually found and removed.

If the response ISR completes the same handle first, it removes the SRB
under qp_lock_ptr and runs sp->done() -> complete(sp->comp). The
submitter qla24xx_control_vp() wakes from wait_for_completion(), clears
sp->comp, drops its reference and returns, reclaiming the on-stack
completion. The timer reference keeps the SRB alive across the timeout
handler, but not the submitter's stack. The timeout then issues a second
sp->done() -> qla_ctrlvp_sp_done(), which evaluates "if (sp->comp)
complete(sp->comp)"; with the pointer loaded before the submitter's NULL
store, complete() writes into the freed stack frame, a use-after-free.

Track whether this path removed the SRB from outstanding_cmds and only
call sp->done() when it did, so the command is completed exactly once by
whichever path owns it. This mirrors the sp_found guard already used in
qla24xx_abort_iocb_timeout().
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via kernel use‑after‑free
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel SCSI driver for QLogic QLA2xxx hosts a flaw in the timeout handling of async IOCBs. The timeout logic unconditionally invokes the completion callback without verifying that the command buffer has been removed from the list of outstanding commands. If the interrupt service routine finishes the command first, the first completion frees the callback structure on the stack. When the timeout handler later calls the same completion function it writes to the already freed stack space, creating a use‑after‑free condition. In kernel contexts a use‑after‑free can be leveraged to execute arbitrary code or elevate privileges to root. The CVSS score of 9.8 reflects the potential for remote privilege escalation once an attacker can trigger the double completion.

Affected Systems

The vulnerability resides in the qla2xxx driver, part of the Linux kernel. It affects any system running a kernel version prior to the patch commit referenced in the advisory. All Linux distributions that ship the affected QLogic SCSI driver are included, regardless of vendor. Specific version ranges are not listed in the advisory, but the kernel code was updated in recent stable releases.

Risk and Exploitability

Based on the description, it is inferred that the attacker must have the ability to send SCSI commands to a QLogic QLA2xxx adapter, which typically requires local privileged access or remote exploitation of a service that interacts with the SCSI subsystem. The EPSS score of less than 1% indicates that the flaw is considered unlikely to be exploited in the wild at present, yet the high CVSS score and lack of KEV listing do not diminish the danger to systems that remain unpatched. Once a command can be timed out, the double‑completion can be triggered to achieve a use‑after‑free and potentially gain kernel execution.

Generated by OpenCVE AI on September 18, 2026 at 09:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the qla2xxx driver patch referenced in the advisory commits.
  • If a full kernel upgrade is not feasible, apply the patch directly to the kernel source tree from the authoritative git references and rebuild the kernel.
  • Until the patch has been applied, unload or disable the qla2xxx driver to prevent the use‑after‑free from being exercised during normal operation.

Generated by OpenCVE AI on September 18, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOCB timeout qla2x00_async_iocb_timeout() tries to abort a timed-out async IOCB. When qla24xx_async_abort_cmd() fails, both the SRB_LOGIN_CMD path and the SRB_CTRL_VP/default path scan outstanding_cmds[] for the SRB and then call sp->done(sp, QLA_FUNCTION_TIMEOUT) unconditionally, without checking whether the SRB was actually found and removed. If the response ISR completes the same handle first, it removes the SRB under qp_lock_ptr and runs sp->done() -> complete(sp->comp). The submitter qla24xx_control_vp() wakes from wait_for_completion(), clears sp->comp, drops its reference and returns, reclaiming the on-stack completion. The timer reference keeps the SRB alive across the timeout handler, but not the submitter's stack. The timeout then issues a second sp->done() -> qla_ctrlvp_sp_done(), which evaluates "if (sp->comp) complete(sp->comp)"; with the pointer loaded before the submitter's NULL store, complete() writes into the freed stack frame, a use-after-free. Track whether this path removed the SRB from outstanding_cmds and only call sp->done() when it did, so the command is completed exactly once by whichever path owns it. This mirrors the sp_found guard already used in qla24xx_abort_iocb_timeout().
Title scsi: qla2xxx: Avoid double completion in async IOCB timeout
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:15.666Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89847

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:51.990

Modified: 2026-09-16T15:18:12.967

Link: CVE-2026-89847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses