PT-2026-94633 · Linux · Linux Kernel
CVE-2026-90285
·
Published
2026-09-17
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
In the scsi qla2xxx driver, the
qla2x00 sysfs read vpd() function performs a redundant call to ha->isp ops->read optrom(). This second call occurs after the optrom mutex has been released, which allows flash access to occur concurrently with other optrom operations, potentially leading to race conditions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel