Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation

ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and
ha->max_qpairs are u8. Deriving the queue count as
"ha->max_req_queues = ha->msix_count - 1" therefore truncates: a board
(or a misconfigured/malicious hot-plugged device) advertising 257 MSI-X
vectors yields msix_count - 1 == 256, which truncates to 0. An MSI-X
count of 1 zeroes it as well, and in target mode the subsequent
"ha->max_req_queues--" then underflows 0 to 255.

When the count is 0, qla2x00_alloc_queues() calls
kzalloc_objs(struct req_que *, 0), which returns ZERO_SIZE_PTR. That is
not NULL, so the allocation check passes and the following
"ha->req_q_map[0] = req" dereferences ZERO_SIZE_PTR, corrupting memory
or crashing the kernel.

Add qla_calc_queue_count() to clamp the derived value into
[1, QLA_MAX_QUEUES - 1] so it always fits in u8 and is never zero, and
use it at all three derivation sites (qla25xx_iospace_config(),
qla83xx_iospace_config() and qla24xx_enable_msix()). Also guard the
target-mode decrement so it cannot reintroduce a zero (which would in
turn underflow max_qpairs).
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption or crash
Action: Immediate Patch
AI Analysis

Impact

The qla2xxx SCSI driver computes the number of request and response queues from the advertised MSI‑X vector count. Because the vector count is stored in a 16‑bit field while the derived queue counts are held in 8‑bit variables, a device announcing more than 256 vectors causes the calculated queue count to be truncated. When the truncation yields zero, the driver allocates a zero‑size queue object, which returns a non‑NULL ZERO_SIZE_PTR. The subsequent assignment to the queue map dereferences this pointer, corrupting kernel memory or causing a kernel panic. This flaw is an integer truncation leading to an invalid pointer dereference and can result in kernel‑level memory corruption or denial of service.

Affected Systems

All Linux kernel releases that bundle the qla2xxx SCSI driver are potentially impacted because the vulnerability is located entirely within the kernel source. No specific vendor, product or version list was supplied, so any distribution shipping a kernel that contains the unpatched qla2xxx driver may be at risk until the fix is applied.

Risk and Exploitability

The CVSS score of 8.4 denotes a high‑severity flaw with local to privileged impact. The EPSS score of <1 % indicates that, as of the latest data, exploitation attempts are unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker would need the ability to introduce a misconfigured or malicious SCSI controller that advertises an anomalous MSI‑X vector count—typically via physical access or trusted hot‑plug. Once triggered, the kernel memory corruption or crash could enable privilege escalation or denial of service.

Generated by OpenCVE AI on September 18, 2026 at 09:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the running Linux kernel to a release that incorporates the qla_calc_queue_count patch, which clamps derived queue counts to a valid range.
  • If an immediate kernel upgrade is not possible, limit all qla2xxx devices to advertise no more than 255 MSI‑X vectors so that the truncation logic never yields zero.
  • Restrict or disable hot‑plugging of SCSI controllers that are not trusted, or configure the system to block devices that supply MSI‑X counts outside the acceptable range.

Generated by OpenCVE AI on September 18, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-681

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and ha->max_qpairs are u8. Deriving the queue count as "ha->max_req_queues = ha->msix_count - 1" therefore truncates: a board (or a misconfigured/malicious hot-plugged device) advertising 257 MSI-X vectors yields msix_count - 1 == 256, which truncates to 0. An MSI-X count of 1 zeroes it as well, and in target mode the subsequent "ha->max_req_queues--" then underflows 0 to 255. When the count is 0, qla2x00_alloc_queues() calls kzalloc_objs(struct req_que *, 0), which returns ZERO_SIZE_PTR. That is not NULL, so the allocation check passes and the following "ha->req_q_map[0] = req" dereferences ZERO_SIZE_PTR, corrupting memory or crashing the kernel. Add qla_calc_queue_count() to clamp the derived value into [1, QLA_MAX_QUEUES - 1] so it always fits in u8 and is never zero, and use it at all three derivation sites (qla25xx_iospace_config(), qla83xx_iospace_config() and qla24xx_enable_msix()). Also guard the target-mode decrement so it cannot reintroduce a zero (which would in turn underflow max_qpairs).
Title scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:20.700Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89856

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:53.440

Modified: 2026-09-16T15:18:13.507

Link: CVE-2026-89856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-681

    Incorrect Conversion between Numeric Types