Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path

qla2x00_sysfs_read_vpd() called ha->isp_ops->read_optrom() a second time
after releasing optrom_mutex. The repeated read is redundant and, unlike
the first, runs without optrom_mutex held, exposing flash access to
concurrent optrom operations. Drop the duplicate call.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Race Condition leading to concurrent flash access potentially corrupting or leaking firmware data
Action: Immediate Patch
AI Analysis

Impact

The qla2xxx SCSI driver in the Linux kernel contains a race condition where a redundant flash read is performed after releasing the optrom mutex. Because the second read occurs without the lock, concurrent optrom operations can access the flash simultaneously, which may corrupt firmware data or leak its contents, undermining both integrity and confidentiality of the device. This flaw is tied to improper synchronization and can allow a compromised system or device to read or modify flash data in an uncontrolled fashion.

Affected Systems

All Linux kernel releases that include the qla2xxx driver before the patch, regardless of distribution, are affected. The vulnerability is tied to the Linux kernel’s SCSI subsystem and therefore applies to any system that loads the qla2xxx driver via the kernel.

Risk and Exploitability

The EPSS score is less than 1 %, and the flaw is not listed in the CISA KEV catalog, indicating that no active exploit is widely known. The likely attack vector is local, requiring either physical access to the device or privileged execution that can trigger concurrent optrom operations. While exploitation could lead to firmware corruption, the ease of attack and overall risk remain moderate in the absence of an identified exploit. The primary concern, however, is the potential for integrity compromise of the flash memory used by the driver.

Generated by OpenCVE AI on September 19, 2026 at 04:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the qla2xxx driver fix
  • If a kernel upgrade cannot be applied immediately, disable or remove the qla2xxx driver until the patch is available
  • Monitor kernel logs for VPD read errors or unexpected behavior that may indicate race condition activity

Generated by OpenCVE AI on September 19, 2026 at 04:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path qla2x00_sysfs_read_vpd() called ha->isp_ops->read_optrom() a second time after releasing optrom_mutex. The repeated read is redundant and, unlike the first, runs without optrom_mutex held, exposing flash access to concurrent optrom operations. Drop the duplicate call.
Title scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:14.661Z

Reserved: 2026-09-11T19:38:34.797Z

Link: CVE-2026-90285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:25.360

Modified: 2026-09-17T17:17:25.360

Link: CVE-2026-90285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:00:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')