Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Serialize flash version read in reset handler

The "update cache versions without reset" sysfs reset operation (0x20261)
calls get_flash_version(), which reads hardware flash registers, without
holding ha->optrom_mutex. The VPD update path serializes the same call
under optrom_mutex, so this reset path can interleave its flash register
accesses with a concurrent VPD or optrom flash operation and corrupt the
reads.

Hold ha->optrom_mutex across the get_flash_version() call to match the
VPD update path.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Race condition in qla2xxx driver that can corrupt flash register reads during device reset
Action: Apply patch
AI Analysis

Impact

During a sysfs reset operation the qla2xxx driver calls the get_flash_version() function without holding the optrom_mutex. The same mutex is used in the VPD update path during flash operations. When these two paths run concurrently, their flash register accesses can interleave, producing corrupted read data. The flaw is a classic data race that leads to inconsistent flash version readings.

Affected Systems

Any Linux kernel distribution that includes the qla2xxx SCSI driver is potentially affected, provided the kernel has not been updated with the patch that serializes the flash version read. No specific version numbers are disclosed, but the fix is available in recent kernel commits as referenced.

Risk and Exploitability

The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. No CVSS score is reported. The attack vector requires simultaneous access to the reset sysfs entry and a VPD or optrom flash operation, which limits remote exploitation possibilities. Overall, the risk of successful exploitation is low given the narrow surface and lack of public exploits.

Generated by OpenCVE AI on September 18, 2026 at 09:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that serializes the flash version read by adding optrom_mutex locking around the get_flash_version() call, as available in the referenced kernel commits.
  • If you compile a custom kernel or module, rebuild the qla2xxx driver after integrating the updated source code to ensure the mutex protection is present.
  • As a temporary precaution, avoid initiating VPD or optrom flash operations while performing a device reset until the kernel is updated.

Generated by OpenCVE AI on September 18, 2026 at 09:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in reset handler The "update cache versions without reset" sysfs reset operation (0x20261) calls get_flash_version(), which reads hardware flash registers, without holding ha->optrom_mutex. The VPD update path serializes the same call under optrom_mutex, so this reset path can interleave its flash register accesses with a concurrent VPD or optrom flash operation and corrupt the reads. Hold ha->optrom_mutex across the get_flash_version() call to match the VPD update path.
Title scsi: qla2xxx: Serialize flash version read in reset handler
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:28.836Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89855

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:53.313

Modified: 2026-09-16T11:16:53.313

Link: CVE-2026-89855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')