Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix BSG job leak on validate flash image error path

qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally,
telling the FC BSG transport (fc_bsg_host_dispatch()) that the driver
owns and will complete the request. But bsg_job_done() is guarded by "if
(!rval)", so on the error path (rval == -EINVAL) neither the driver nor
the transport completes the job. The request dangles until it times out,
leaking block layer resources.

Commit c2c68225b145 ("scsi: qla2xxx: Fix bsg_done() causing double
free") added the "if (!rval)" guard to a batch of BSG handlers. That is
correct for handlers that also return the error code (the transport then
completes the job once via fail_host_msg), but this function returns
QLA_SUCCESS unconditionally, so the guard turned a correct single
completion into a leak.

Always call bsg_job_done(): bsg_reply->result is DID_OK and the error is
reported in vendor_rsp[0], and since the function returns 0 the
transport will not complete the job a second time.
Published: 2026-09-16
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Patch
AI Analysis

Impact

The qla2xxx SCSI driver in the Linux kernel contains a flaw that causes a Block Store Generic (BSG) job to be leaked when a flash image validation fails. The validate_flash_image routine unconditionally reports success, preventing bsg_job_done from being invoked on the error path. This leaves BSG requests dangling until they time out, gradually exhausting block‑layer resources and potentially disrupting legitimate storage operations.

Affected Systems

All Linux kernel installations that include the qla2xxx driver without the later commit that restores bsg_job_done are affected. No specific kernel releases are enumerated, so any kernel build predating the patch is considered vulnerable, regardless of the vendor or distribution.

Risk and Exploitability

The CVSS score of 5.5 and an EPSS score of less than 1 % indicate a moderate severity but a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require interaction with the SCSI transport layer on a system that has a qla2xxx device, suggesting a local or privileged attack vector. While an attacker could trigger repeated leaks to deplete kernel resources, the practical difficulty of continuously invoking the error path keeps overall risk modest.

Generated by OpenCVE AI on September 24, 2026 at 03:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit c2c68225b145 which restores proper bsg_job_done handling in qla2xxx.
  • If a kernel upgrade is not possible, configure the qla2xxx driver or the associated device to disable or limit flash image validation so the error path is never exercised.
  • If neither of the above is feasible, isolate the affected device or restrict its usage to prevent potential resource exhaustion attacks.

Generated by OpenCVE AI on September 24, 2026 at 03:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix BSG job leak on validate flash image error path qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally, telling the FC BSG transport (fc_bsg_host_dispatch()) that the driver owns and will complete the request. But bsg_job_done() is guarded by "if (!rval)", so on the error path (rval == -EINVAL) neither the driver nor the transport completes the job. The request dangles until it times out, leaking block layer resources. Commit c2c68225b145 ("scsi: qla2xxx: Fix bsg_done() causing double free") added the "if (!rval)" guard to a batch of BSG handlers. That is correct for handlers that also return the error code (the transport then completes the job once via fail_host_msg), but this function returns QLA_SUCCESS unconditionally, so the guard turned a correct single completion into a leak. Always call bsg_job_done(): bsg_reply->result is DID_OK and the error is reported in vendor_rsp[0], and since the function returns 0 the transport will not complete the job a second time.
Title scsi: qla2xxx: Fix BSG job leak on validate flash image error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:33.698Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89862

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:54.237

Modified: 2026-09-16T11:16:54.237

Link: CVE-2026-89862

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-89862 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T03:45:14Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime