Database/Kernel, userspace & hypervisor
Linux kernel qla2xxx: unserialized NVMe-FC unsolicited-context list can be corrupted by concurrent add and delete
Impact
The per-fcport unsol_ctx_head list in the QLogic qla2xxx Fibre Channel driver is modified from four contexts with no common lock: entries are added from the response-queue ISR under the qpair qp_lock, and removed from the DPC/purex worker, the NVMe-FC transport callback and SRB completion. On a multiqueue HBA the adds arrive through different qpairs, so qp_lock cannot serialize the list and a concurrent add and delete - or two deletes - corrupts the list pointers. The fix adds a dedicated per-fcport unsol_ctx_lock around every list_add_tail()/list_del(). The practical consequence on a storage node is list corruption leading to a kernel panic or worse under FC-NVMe traffic, which takes the node and its attached storage path down; GPU nodes that boot from or stage datasets over FC-NVMe lose the array with it. Triggering depends on FC fabric traffic timing rather than on anything a tenant process controls - NVD's AV:A adjacent score reflects the fabric, not a tenant pod. Nodes without qla2xxx FC HBAs or without FC-NVMe are unaffected.
Who can reach it
Requires a system running the qla2xxx driver with FC-NVMe in use; the race is driven by unsolicited LS traffic arriving from the Fibre Channel fabric, so it needs presence on that fabric rather than any login to the host. Not reachable by an unprivileged local user or a tenant GPU pod.
What to do
Update to a stable kernel carrying the linked commits and reboot each affected node. A qla2xxx module reload is theoretically narrower but not practical on a node whose root or dataset storage is behind the HBA, so in the field this is drain-and-reboot per storage-attached node. There is no configuration mitigation short of not using FC-NVMe on that path.
References
Related entries
- Linux kernel qla2xxx: NVMe-FC unsolicited context freed while still linked, leaving a freed node on the listCVE-2026-97528 · Linux kernel scsi qla2xxx (uctx freed without list_del() on qla_nvme_xmt_ls_rsp() error path)High
- Linux kernel mlx5_core representor TC path + net/sched tc extension: The TC_SKB_EXT skb extension is not zeroedCVE-2021-47136 · Linux kernel mlx5_core representor TC path + net/sched tc extensionHigh
- Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLSCVE-2025-38608 · Linux kernel (net/tls)High
- Linux kernel libceph: truncated monitor reply decodes stale bytes from the reused bufferCVE-2026-68433 · Linux kernel libceph (MON_GET_VERSION_REPLY decode bound)High
- sudo: intercept policy checks skipped for execveat, letting allowed users run denied commandsCVE-2026-82474 · sudo (ptrace-based intercept mode, execveat/fexecve path)High
- Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVMCVE-2024-50115 · Linux kernel (arch/x86/kvm/svm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.