PT-2026-98471 · Linux · Linux
CVE-2026-97531
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Skip vport under deletion in report ID acquisition
qla24xx report id acquisition() format-1 handling walks ha->vp list under
vport slock, takes a vref count on the matching vport and calls
qla update host map() to register its port id.
A vport teardown via qla24xx vport delete() sets VPORT DELETE, then
qla24xx disable vp() removes the vport from the host map btree and zeroes
vha->d id (RESET AL PA). The vport is only unlinked from vp list later,
in qla24xx deallocate vp id(), which clears vp map[idx] (RESET VP IDX)
but does not touch host map. In the window in between, report ID
acquisition can still find the vport on vp list and call
qla update host map(); with d id already zeroed it takes the
btree insert32() path and re-inserts the dying vport into host map.
Nothing cleans that entry afterwards, so once scsi host put() frees the
vha a later host map lookup dereferences freed memory.
Skip a vport that has VPORT DELETE set before taking the reference, so it
is neither re-registered nor scheduled for DPC re-registration. This
mirrors the existing guard in qla2x00 alert all vps().
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux