CVE-2026-89848 PUBLISHED

scsi: qla2xxx: Quiesce response IRQ before freeing request queue

Assigner: Linux
Reserved: 11.09.2026 Published: 16.09.2026 Updated: 16.09.2026

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Quiesce response IRQ before freeing request queue

qla2xxx_delete_qpair() deletes the request queue before the response queue. qla25xx_delete_req_que() frees the request queue memory (kfree(req) in qla25xx_free_req_que()), but the response-queue MSI-X is only released later, in qla25xx_free_rsp_que(). In that window the response interrupt can still fire, qla2xxx_msix_rsp_q() queues qpair->q_work, and qla_do_work() -> qla24xx_process_response_queue() dereferences the now-freed rsp->req (LOGINOUT/CT/ELS entries and the status path), a use-after-free.

The cancel_work_sync() added for the qpair teardown lives in the response free path, which runs after the request queue is already freed, so it does not protect rsp->req.

Release the response-queue interrupt and flush qpair->q_work before deleting the request queue, so no late completion can reach the freed request queue. Clearing have_irq makes the subsequent qla25xx_free_rsp_que() skip its free_irq(), and the firmware queue-delete order (request then response) is preserved; the request-delete mailbox completes on the default vector and is unaffected by dropping the qpair response interrupt early.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

AV:N - qla24xx_process_response_queue() runs from the qla2xxx response-queue MSI-X/work path on firmware-DMAed LOGINOUT/CT/ELS/status IOCBs from Fibre Channel, FCoE, or FCIP traffic; a remote SAN peer can induce those completions without a local syscall, matching sibling CVE-2026-89845 Network scoring of the same teardown window. AC:H - The use-after-free requires qla25xx_free_req_que() to kfree the request queue while the response MSI-X is still registered, which occurs only during qpair, NPIV vport, or device teardown, a victim state a fabric attacker cannot initiate. PR:N - Response-queue interrupt handling of LOGINOUT/CT/ELS/status completions runs from unauthenticated Fibre Channel firmware IOCBs with no Linux credential or capability check, so a fabric peer needs no account on the victim host. UI:N - Response-queue interrupt handling is automatic; concurrent qpair teardown occurs during routine driver remove, NPIV vport deletion, or PCI removal without interactive victim actions such as mounting a filesystem. S:U - The use-after-free is inside the host kernel qla2xxx driver and does not cross a VM, IOMMU, or other separate security-authority boundary. C:H - After kfree(req), rsp->req remains dangling and qla_get_sp_from_handle() reads req->num_outstanding_cmds and req->outstanding_cmds[]; that request-queue use-after-free enables disclosure of reused heap contents. I:H - qla2x00_get_sp_from_handle() writes NULL into the freed outstanding_cmds slot, and subsequent LOGINOUT/CT/ELS completion handling operates on a recycled req/srb object, yielding a kernel write and control-flow hijack primitive. A:H - Use-after-free of the request queue from qla_do_work()/qla24xx_process_response_queue produces a kernel oops or panic even when not fully exploited, taking down storage served by the adapter.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d74595278f4ab192af66d9e60a9087464638beee to 7ac5be2a8609679fc6bbfea881360444a5ce8202 (excl.)
  • affected from d74595278f4ab192af66d9e60a9087464638beee to 1486cc18be3e2b4c2a730f4a1b0448d009381b3d (excl.)
  • affected from d74595278f4ab192af66d9e60a9087464638beee to 10e9f05f7fd0a103886a867ec8afe621fe4b906a (excl.)
  • affected from d74595278f4ab192af66d9e60a9087464638beee to 157ca7d1af45f87aa14a286754f19c3f72386988 (excl.)
  • affected from d74595278f4ab192af66d9e60a9087464638beee to 505753ec2594c6af09a601f0dd60be7d840c1d2d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.10 is affected
  • unaffected from 0 to 4.10 (excl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.51 to 6.18.* (incl.)
  • unaffected from 7.2.5 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References