PT-2026-98469 · Linux · Linux Kernel
CVE-2026-97529
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the scsi qla2xxx driver where the FC BSG transport allocates
job->request using a user-supplied request len via memdup user(). For FC BSG HST VENDOR, the fc bsg host dispatch() function only ensures that request len covers the message code and vendor ID, failing to account for the vendor cmd[] flexible array. Consequently, the driver reads the command selector vendor cmd[0] and other elements in various sub-handlers without verifying the request len. A user with CAP SYS RAWIO privileges can submit a short request with a matching vendor ID to trigger out-of-bounds heap reads, which may lead to command mis-selection or a system panic. The affected sub-handlers include qla24xx proc fcp prio cfg cmd(), qla2x00 process loopback(), qla84xx reset(), qla84xx updatefw(), qla2x00 read optrom(), qla2x00 update optrom(), qlafx00 mgmt cmd(), and qla28xx validate flash image().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel