Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path

qla2x00_status_entry() filters out non-TYPE_SRB entries and the
SRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a
SCSI fast path that assumes the command is an SRB_SCSI_CMD. The first
thing on that path, qla_chk_edif_rx_sa_delete_pending(), and the
subsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd.

The srb u union overlays the SCSI command pointer with other command
layouts (bsg_job, iocb_cmd). If firmware delivers an unexpected
STATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a
non-NULL garbage pointer, bypassing the NULL checks in
qla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and
leading to a wild pointer dereference.

Reject any SRB whose type is not SRB_SCSI_CMD before entering the fast
path. The outstanding_cmds slot is left untouched so a genuinely
non-SCSI command still completes through its proper handler.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash and denial of service
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s qla2xxx SCSI target driver. When handling status IOCBs, the code path assumes all commands are of type SRB_SCSI_CMD and accesses the command pointer through a union overlay. If firmware delivers an unexpected STATUS_TYPE IOCB for a non‑SCSI handle, the union can expose garbage as a non‑NULL pointer, bypassing null checks and ultimately dereferencing an invalid pointer. This results in a wild pointer dereference that can crash the kernel or corrupt memory, thereby denying service or potentially allowing privilege escalation if the crash can be repeatedly triggered.

Affected Systems

All Linux kernel distributions that ship the unpatched qla2xxx driver are affected. The flaw is present in the generic Linux kernel code, so any system using the qla2xxx adapter without the patch is vulnerable. Since the vendor list shows Linux:Linux twice, the issue applies across all Linux kernel versions before the fix.

Risk and Exploitability

The CVSS score of 8.8 reflects high severity, while the EPSS score of less than 1% indicates a low probability of real‑world exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploits exist. The likely attack vector involves local or device‑privileged access to a controller that can inject a malformed status IOCB; attackers would need to bypass normal firmware validation to trigger the pointer dereference.

Generated by OpenCVE AI on September 18, 2026 at 09:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the qla2xxx driver fix that adds type checking before the fast path.
  • If a kernel update cannot be applied immediately, disable or unload the qla2xxx module to prevent the vulnerability from being exercised until a patch is available.
  • Verify that firmware on SCSI adapters is configured or updated to enforce strict type validation before issuing status IOCBs, reducing the chance of malformed commands reaching the driver.

Generated by OpenCVE AI on September 18, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-666

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path qla2x00_status_entry() filters out non-TYPE_SRB entries and the SRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a SCSI fast path that assumes the command is an SRB_SCSI_CMD. The first thing on that path, qla_chk_edif_rx_sa_delete_pending(), and the subsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd. The srb u union overlays the SCSI command pointer with other command layouts (bsg_job, iocb_cmd). If firmware delivers an unexpected STATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a non-NULL garbage pointer, bypassing the NULL checks in qla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and leading to a wild pointer dereference. Reject any SRB whose type is not SRB_SCSI_CMD before entering the fast path. The outstanding_cmds slot is left untouched so a genuinely non-SCSI command still completes through its proper handler.
Title scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:18.117Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89849

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:52.497

Modified: 2026-09-16T15:18:13.230

Link: CVE-2026-89849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-666

    Operation on Resource in Wrong Phase of Lifetime