Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix cs84xx use-after-free on host teardown

qla84xx_put_chip() drops the last reference to ha->cs84xx and frees it via
__qla84xx_chip_release() without clearing ha->cs84xx. During teardown it ran
before scsi_remove_host(), which is what removes the 84xx_fw_version host
sysfs attribute. A concurrent read of that attribute in the window between
the two calls executes qla24xx_84xx_fw_version_show(), which dereferences
the freed ha->cs84xx, resulting in a use-after-free.

Move qla84xx_put_chip() to after scsi_remove_host() in both
qla2x00_remove_one() and qla2x00_disable_board_on_pci_error(). Once
scsi_remove_host() returns, the sysfs attribute is gone and kernfs has
drained any in-flight show(), so no reader can touch cs84xx; the put still
runs before the host and ha are freed.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption / potential arbitrary code execution
Action: Apply patch
AI Analysis

Impact

During a SCSI host teardown, the qla84xx_put_chip() function releases a reference to the cs84xx structure without clearing its pointer. This occurs before scsi_remove_host() removes the sysfs attribute that exposes the fw_version. A concurrent read of that attribute can therefore dereference freed memory, causing a use‑after‑free. If an attacker can trigger the race condition, the resulting kernel memory corruption can lead to arbitrary code execution or a local denial‑of‑service, as the fault occurs in kernel space.

Affected Systems

The vulnerability is present in the Linux kernel for all distributions that ship the qla2xxx SCSI driver, including the qla84xx code. It affects any system that loads the qla2xxx module before the kernel patch is applied. No specific kernel version is listed, so all affected kernels that include the unpatched driver code are at risk.

Risk and Exploitability

The CVSS base score of 7.8 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not in the CISA KEV catalog. The attack requires a local user who can manipulate the SCSI host teardown process and read the sysfs attribute simultaneously, making it a privilege‑escalation or local exploitation vector. While the risk is moderate, it remains important to apply the patch promptly.

Generated by OpenCVE AI on September 18, 2026 at 08:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the patch for this vulnerability.
  • If an update is not yet available, unload or disable the qla2xxx kernel module until a fixed kernel is installed.
  • Verify that sysfs attributes for SCSI hosts are not exposed to non‑privileged users, and remove or restrict them if possible.

Generated by OpenCVE AI on September 18, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix cs84xx use-after-free on host teardown qla84xx_put_chip() drops the last reference to ha->cs84xx and frees it via __qla84xx_chip_release() without clearing ha->cs84xx. During teardown it ran before scsi_remove_host(), which is what removes the 84xx_fw_version host sysfs attribute. A concurrent read of that attribute in the window between the two calls executes qla24xx_84xx_fw_version_show(), which dereferences the freed ha->cs84xx, resulting in a use-after-free. Move qla84xx_put_chip() to after scsi_remove_host() in both qla2x00_remove_one() and qla2x00_disable_board_on_pci_error(). Once scsi_remove_host() returns, the sysfs attribute is gone and kernfs has drained any in-flight show(), so no reader can touch cs84xx; the put still runs before the host and ha are freed.
Title scsi: qla2xxx: Fix cs84xx use-after-free on host teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:19.342Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89854

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:53.180

Modified: 2026-09-16T15:18:13.367

Link: CVE-2026-89854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:00:14Z

Weaknesses