Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()

In the format 1 path, the virtual port is located on ha->vp_list while
holding vport_slock, but the lock is dropped before vp is used:
qla_update_host_map() is called and VP_IDX_ACQUIRED/REGISTER_FC4_NEEDED/
REGISTER_FDMI_NEEDED are set on vp. No reference is taken across that
window, so a concurrent qla24xx_deallocate_vp_id() can tear the vport
down and free it, leading to a use-after-free.

Take a vport reference (vref_count) under vport_slock when the matching
vp is found, and drop it after the last use of
vp. qla24xx_deallocate_vp_id() waits for vref_count to reach zero before
unlinking and freeing the vport, so the pointer stays valid. This
matches the reference idiom already used by the other ha->vp_list
traversals.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free
Action: Patch Immediately
AI Analysis

Impact

The qla2xxx SCSI driver contains a race condition that allows a virtual port (vport) to be freed while still in use. During an ID acquisition the driver releases a lock before taking a reference on the vport, creating a window where a concurrent deallocation can remove the port and release its memory, leading to a use‑after‑free in kernel space and potential memory corruption. This flaw is represented by CWE-416 and can compromise kernel image integrity if exploited.

Affected Systems

All Linux system images that include the default qla2xxx SCSI driver are affected. The CVE description does not list specific kernel releases or distribution names; therefore any distribution that ships the driver unmodified, across current and past kernel versions, may be vulnerable. No version constraints are supplied by the CNA, so the impact may span all kernel releases that contain the old qla2xxx code.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and the EPSS score of <1% suggests that the probability of exploitation is very low according to current metrics. The CISA KEV catalog does not list this vulnerability. The likely attack vector is inferred: a malicious or compromised entity that can issue SCSI commands through the qla2xxx driver—such as a local attacker with privileged access to the host bus adapter or a remote attacker able to interact with the SCSI layer—could trigger the race condition. More information about the exact attack surface is not present in the CVE data and must be determined through further analysis.

Generated by OpenCVE AI on September 18, 2026 at 09:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the qla2xxx reference‑hold patch or cherry‑pick the upstream commit that implements the fix.
  • If an update is not possible, unload or blacklist the qla2xxx module to eliminate the race condition until a patched kernel is available.
  • Restrict SCSI device access to trusted users only or disable the qla2xxx driver on hosts where it is not required to reduce attack surface.

Generated by OpenCVE AI on September 18, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() In the format 1 path, the virtual port is located on ha->vp_list while holding vport_slock, but the lock is dropped before vp is used: qla_update_host_map() is called and VP_IDX_ACQUIRED/REGISTER_FC4_NEEDED/ REGISTER_FDMI_NEEDED are set on vp. No reference is taken across that window, so a concurrent qla24xx_deallocate_vp_id() can tear the vport down and free it, leading to a use-after-free. Take a vport reference (vref_count) under vport_slock when the matching vp is found, and drop it after the last use of vp. qla24xx_deallocate_vp_id() waits for vref_count to reach zero before unlinking and freeing the vport, so the pointer stays valid. This matches the reference idiom already used by the other ha->vp_list traversals.
Title scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:24.344Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:54.100

Modified: 2026-09-16T15:18:13.917

Link: CVE-2026-89861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses