GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel qla2xxx: unserialized NVMe-FC unsolicited-context list can be corrupted by concurrent add and delete

CVSS 8.8CVE-2026-97527Kernel, userspace & hypervisorcurated

Impact

The per-fcport unsol_ctx_head list in the QLogic qla2xxx Fibre Channel driver is modified from four contexts with no common lock: entries are added from the response-queue ISR under the qpair qp_lock, and removed from the DPC/purex worker, the NVMe-FC transport callback and SRB completion. On a multiqueue HBA the adds arrive through different qpairs, so qp_lock cannot serialize the list and a concurrent add and delete - or two deletes - corrupts the list pointers. The fix adds a dedicated per-fcport unsol_ctx_lock around every list_add_tail()/list_del(). The practical consequence on a storage node is list corruption leading to a kernel panic or worse under FC-NVMe traffic, which takes the node and its attached storage path down; GPU nodes that boot from or stage datasets over FC-NVMe lose the array with it. Triggering depends on FC fabric traffic timing rather than on anything a tenant process controls - NVD's AV:A adjacent score reflects the fabric, not a tenant pod. Nodes without qla2xxx FC HBAs or without FC-NVMe are unaffected.

Who can reach it

Requires a system running the qla2xxx driver with FC-NVMe in use; the race is driven by unsolicited LS traffic arriving from the Fibre Channel fabric, so it needs presence on that fabric rather than any login to the host. Not reachable by an unprivileged local user or a tenant GPU pod.

What to do

Update to a stable kernel carrying the linked commits and reboot each affected node. A qla2xxx module reload is theoretically narrower but not practical on a node whose root or dataset storage is behind the HBA, so in the field this is drain-and-reboot per storage-attached node. There is no configuration mitigation short of not using FC-NVMe on that path.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.