PT-2026-98469 · Linux · Linux Kernel

CVE-2026-97529

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the scsi qla2xxx driver where the FC BSG transport allocates job->request using a user-supplied request len via memdup user(). For FC BSG HST VENDOR, the fc bsg host dispatch() function only ensures that request len covers the message code and vendor ID, failing to account for the vendor cmd[] flexible array. Consequently, the driver reads the command selector vendor cmd[0] and other elements in various sub-handlers without verifying the request len. A user with CAP SYS RAWIO privileges can submit a short request with a matching vendor ID to trigger out-of-bounds heap reads, which may lead to command mis-selection or a system panic. The affected sub-handlers include qla24xx proc fcp prio cfg cmd(), qla2x00 process loopback(), qla84xx reset(), qla84xx updatefw(), qla2x00 read optrom(), qla2x00 update optrom(), qlafx00 mgmt cmd(), and qla28xx validate flash image().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97529

Affected Products

Linux Kernel