In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Quiesce response IRQ before freeing request queue
qla2xxx_delete_qpair() deletes the request queue before the response
queue. qla25xx_delete_req_que() frees the request queue memory
(kfree(req) in qla25xx_free_req_que()), but the response-queue MSI-X is
only released later, in qla25xx_free_rsp_que(). In that window the
response interrupt can still fire, qla2xxx_msix_rsp_q() queues
qpair->q_work, and qla_do_work() -> qla24xx_process_response_queue()
dereferences the now-freed rsp->req (LOGINOUT/CT/ELS entries and the
status path), a use-after-free.
The cancel_work_sync() added for the qpair teardown lives in the
response free path, which runs after the request queue is already freed,
so it does not protect rsp->req.
Release the response-queue interrupt and flush qpair->q_work before
deleting the request queue, so no late completion can reach the freed
request queue. Clearing have_irq makes the subsequent
qla25xx_free_rsp_que() skip its free_irq(), and the firmware
queue-delete order (request then response) is preserved; the
request-delete mailbox completes on the default vector and is unaffected
by dropping the qpair response interrupt early.
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1
AV:N - qla24xx_process_response_queue() runs from the qla2xxx response-queue MSI-X/work path on firmware-DMAed LOGINOUT/CT/ELS/status IOCBs from Fibre Channel, FCoE, or FCIP traffic; a remote SAN peer can induce those completions without a local syscall, matching sibling CVE-2026-89845 Network scoring of the same teardown window.
AC:H - The use-after-free requires qla25xx_free_req_que() to kfree the request queue while the response MSI-X is still registered, which occurs only during qpair, NPIV vport, or device teardown, a victim state a fabric attacker cannot initiate.
PR:N - Response-queue interrupt handling of LOGINOUT/CT/ELS/status completions runs from unauthenticated Fibre Channel firmware IOCBs with no Linux credential or capability check, so a fabric peer needs no account on the victim host.
UI:N - Response-queue interrupt handling is automatic; concurrent qpair teardown occurs during routine driver remove, NPIV vport deletion, or PCI removal without interactive victim actions such as mounting a filesystem.
S:U - The use-after-free is inside the host kernel qla2xxx driver and does not cross a VM, IOMMU, or other separate security-authority boundary.
C:H - After kfree(req), rsp->req remains dangling and qla_get_sp_from_handle() reads req->num_outstanding_cmds and req->outstanding_cmds[]; that request-queue use-after-free enables disclosure of reused heap contents.
I:H - qla2x00_get_sp_from_handle() writes NULL into the freed outstanding_cmds slot, and subsequent LOGINOUT/CT/ELS completion handling operates on a recycled req/srb object, yielding a kernel write and control-flow hijack primitive.
A:H - Use-after-free of the request queue from qla_do_work()/qla24xx_process_response_queue produces a kernel oops or panic even when not fully exploited, taking down storage served by the adapter.
| Attack Vector |
Network |
Scope |
Unchanged |
| Attack Complexity |
High |
Confidentiality Impact |
High |
| Privileges Required |
None |
Integrity Impact |
High |
| User Interaction |
None |
Availability Impact |
High |
AV:N - qla24xx_process_response_queue() runs from the qla2xxx response-queue MSI-X/work path on firmware-DMAed LOGINOUT/CT/ELS/status IOCBs from Fibre Channel, FCoE, or FCIP traffic; a remote SAN peer can induce those completions without a local syscall, matching sibling CVE-2026-89845 Network scoring of the same teardown window.
AC:H - The use-after-free requires qla25xx_free_req_que() to kfree the request queue while the response MSI-X is still registered, which occurs only during qpair, NPIV vport, or device teardown, a victim state a fabric attacker cannot initiate.
PR:N - Response-queue interrupt handling of LOGINOUT/CT/ELS/status completions runs from unauthenticated Fibre Channel firmware IOCBs with no Linux credential or capability check, so a fabric peer needs no account on the victim host.
UI:N - Response-queue interrupt handling is automatic; concurrent qpair teardown occurs during routine driver remove, NPIV vport deletion, or PCI removal without interactive victim actions such as mounting a filesystem.
S:U - The use-after-free is inside the host kernel qla2xxx driver and does not cross a VM, IOMMU, or other separate security-authority boundary.
C:H - After kfree(req), rsp->req remains dangling and qla_get_sp_from_handle() reads req->num_outstanding_cmds and req->outstanding_cmds[]; that request-queue use-after-free enables disclosure of reused heap contents.
I:H - qla2x00_get_sp_from_handle() writes NULL into the freed outstanding_cmds slot, and subsequent LOGINOUT/CT/ELS completion handling operates on a recycled req/srb object, yielding a kernel write and control-flow hijack primitive.
A:H - Use-after-free of the request queue from qla_do_work()/qla24xx_process_response_queue produces a kernel oops or panic even when not fully exploited, taking down storage served by the adapter.
CVSS 3.1