Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Don't query firmware state while chip is down

qla2x00_fw_state_show() initializes rval to QLA_FUNCTION_FAILED and jumps
to the out: label when the chip is down or EEH is busy. The out: block
then re-issued qla2x00_get_firmware_state() because rval != QLA_SUCCESS,
defeating the chip-down/EEH-busy guards and issuing a mailbox command
(outside optrom_mutex) during ISP reset or PCI error recovery, which can
hang the adapter. It also turned a normal in-lock mailbox failure into a
second unsynchronized mailbox attempt.

Make the out: fallback only mark the firmware state as unknown. The
mailbox is now issued at most once, inside optrom_mutex, and only when
the chip is up and not EEH-busy.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The qla2xxx SCSI driver in the Linux kernel contains a logic flaw that causes it to send a second mailbox command to a Q Logic adapter when the chip is down or EEH busy. This command is issued outside the optrom_mutex lock and can trigger a hang during ISP reset or PCI error recovery, effectively rendering the device unusable. The bug turns an otherwise harmless mailbox failure into a second unsynchronised attempt, resulting in a denial‑of‑service condition for any host using the affected adapter.

Affected Systems

The flaw exists in the kernel’s qla2xxx driver code that is part of all Linux kernels using the unpatched driver. Consequently any Linux installation with a Q Logic SCSI adapter connected is affected until the driver is updated to the patch that removes the second command and restricts mailbox issuance to a valid chip state. No specific version range is supplied, so the vulnerability applies to all kernels that include the buggy code.

Risk and Exploitability

The EPSS score indicates a probability of exploitation below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting low attacker interest. The flaw would require local privilege or kernel‑level execution to trigger the erroneous mailbox request; therefore the exploit path is limited, though an attacker who succeeds could force a complete adapter hang, causing a denial of service for the host. Overall risk is low, but for environments that rely on uninterrupted SCSI storage this defect can be critical.

Generated by OpenCVE AI on September 18, 2026 at 09:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Immediately update the kernel to a version that contains the qla2xxx driver patch (commit 178d984e8875292582e4295cf559b2b11d3c9325 or later).
  • If a kernel update is not feasible, disable or remove the affected Q Logic adapter or unload the qla2xxx driver module until a patched kernel is available.
  • Configure system monitoring to detect stuck SCSI commands and trigger an automated reboot or failover when the adapter hangs.

Generated by OpenCVE AI on September 18, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-727
CWE-755

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Don't query firmware state while chip is down qla2x00_fw_state_show() initializes rval to QLA_FUNCTION_FAILED and jumps to the out: label when the chip is down or EEH is busy. The out: block then re-issued qla2x00_get_firmware_state() because rval != QLA_SUCCESS, defeating the chip-down/EEH-busy guards and issuing a mailbox command (outside optrom_mutex) during ISP reset or PCI error recovery, which can hang the adapter. It also turned a normal in-lock mailbox failure into a second unsynchronized mailbox attempt. Make the out: fallback only mark the firmware state as unknown. The mailbox is now issued at most once, inside optrom_mutex, and only when the chip is up and not EEH-busy.
Title scsi: qla2xxx: Don't query firmware state while chip is down
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:24.121Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:52.623

Modified: 2026-09-16T11:16:52.623

Link: CVE-2026-89850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses