Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Quiesce response IRQ before freeing request queue

qla2xxx_delete_qpair() deletes the request queue before the response
queue. qla25xx_delete_req_que() frees the request queue memory
(kfree(req) in qla25xx_free_req_que()), but the response-queue MSI-X is
only released later, in qla25xx_free_rsp_que(). In that window the
response interrupt can still fire, qla2xxx_msix_rsp_q() queues
qpair->q_work, and qla_do_work() -> qla24xx_process_response_queue()
dereferences the now-freed rsp->req (LOGINOUT/CT/ELS entries and the
status path), a use-after-free.

The cancel_work_sync() added for the qpair teardown lives in the
response free path, which runs after the request queue is already freed,
so it does not protect rsp->req.

Release the response-queue interrupt and flush qpair->q_work before
deleting the request queue, so no late completion can reach the freed
request queue. Clearing have_irq makes the subsequent
qla25xx_free_rsp_que() skip its free_irq(), and the firmware
queue-delete order (request then response) is preserved; the
request-delete mailbox completes on the default vector and is unaffected
by dropping the qpair response interrupt early.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-after-free leading to kernel crash and denial of service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel's qla2xxx SCSI driver, the code releases the response‑queue MSI‑X interrupt after the request queue has already been freed. While the legacy request queue is available, a response interrupt can still arrive, causing the driver’s work function to run and dereference freed memory. These dereferences access objects that no longer exist, triggering a use‑after‑free that can corrupt the kernel or cause a system crash. The flaw is a classic memory corruption vulnerability that can lead to denial‑of‑service if exploited.

Affected Systems

Any Linux kernel that includes the unpatched qla2xxx driver is vulnerable. The advisory references several upstream commits that address the issue, so any distribution whose kernel has not yet incorporated those commits will remain at risk. The vulnerability applies to all Linux distributions that ship this driver for QLogic SCSI adapters, regardless of version, until the fixes are integrated.

Risk and Exploitability

The CVSS score of 8.1 classifies the flaw as high severity. The EPSS score of less than 1% indicates that exploitation is currently uncommon. The issue is not listed in CISA’s KEV catalog. Exploitation requires local or privileged access to the QLogic host bus adapter; an attacker who can inject SCSI commands or control the initiator side of the fabric can trigger the race window and cause a kernel crash or denial of service. Since the flaw depends on timing between interrupt handling and memory free, it is generally considered a local escalation vector.

Generated by OpenCVE AI on September 18, 2026 at 09:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the QLogic driver patches referenced in the advisory.
  • If an immediate kernel upgrade is not possible, unload or disable the qla2xxx module to prevent the vulnerable code from executing.
  • Monitor system logs for kernel oops or panic messages and apply a patch as soon as available.

Generated by OpenCVE AI on September 18, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Quiesce response IRQ before freeing request queue qla2xxx_delete_qpair() deletes the request queue before the response queue. qla25xx_delete_req_que() frees the request queue memory (kfree(req) in qla25xx_free_req_que()), but the response-queue MSI-X is only released later, in qla25xx_free_rsp_que(). In that window the response interrupt can still fire, qla2xxx_msix_rsp_q() queues qpair->q_work, and qla_do_work() -> qla24xx_process_response_queue() dereferences the now-freed rsp->req (LOGINOUT/CT/ELS entries and the status path), a use-after-free. The cancel_work_sync() added for the qpair teardown lives in the response free path, which runs after the request queue is already freed, so it does not protect rsp->req. Release the response-queue interrupt and flush qpair->q_work before deleting the request queue, so no late completion can reach the freed request queue. Clearing have_irq makes the subsequent qla25xx_free_rsp_que() skip its free_irq(), and the firmware queue-delete order (request then response) is preserved; the request-delete mailbox completes on the default vector and is unaffected by dropping the qpair response interrupt early.
Title scsi: qla2xxx: Quiesce response IRQ before freeing request queue
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:16.899Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89848

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:52.197

Modified: 2026-09-16T15:18:13.107

Link: CVE-2026-89848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses