PT-2026-98476 · Linux · Linux Kernel

CVE-2026-97536

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the scsi qla2xxx driver during queue teardown. The response queue MSI-X handler qla2xxx msix rsp q() schedules the qla do work() function via queue work(ha->wq, &qpair->q work), which subsequently dereferences the qpair and acquires qpair->qp lock. During the teardown process, qla2xxx delete qpair() deletes the response queue by calling free irq() in qla25xx free rsp que() and then frees the queue and the qpair. Because free irq() does not cancel work already placed on ha->wq, a pending q work may execute qla do work() using the freed qpair and response queue. This scenario is particularly likely during full adapter teardown when destroy workqueue(ha->wq) forces pending work to run after the queue pairs have been released.
Recommendations As a temporary mitigation, restrict operations that trigger full adapter teardown or queue deletion until the system is updated. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97536

Affected Products

Linux Kernel