PT-2026-98471 · Linux · Linux

CVE-2026-97531

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Skip vport under deletion in report ID acquisition
qla24xx report id acquisition() format-1 handling walks ha->vp list under vport slock, takes a vref count on the matching vport and calls qla update host map() to register its port id.
A vport teardown via qla24xx vport delete() sets VPORT DELETE, then qla24xx disable vp() removes the vport from the host map btree and zeroes vha->d id (RESET AL PA). The vport is only unlinked from vp list later, in qla24xx deallocate vp id(), which clears vp map[idx] (RESET VP IDX) but does not touch host map. In the window in between, report ID acquisition can still find the vport on vp list and call qla update host map(); with d id already zeroed it takes the btree insert32() path and re-inserts the dying vport into host map. Nothing cleans that entry afterwards, so once scsi host put() frees the vha a later host map lookup dereferences freed memory.
Skip a vport that has VPORT DELETE set before taking the reference, so it is neither re-registered nor scheduled for DPC re-registration. This mirrors the existing guard in qla2x00 alert all vps().

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97531

Affected Products

Linux