GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel qla2xxx: NVMe-FC unsolicited context freed while still linked, leaving a freed node on the list

CVSS 8.8CVE-2026-97528Kernel, userspace & hypervisorcurated

Impact

On the error path of qla_nvme_xmt_ls_rsp(), the qla2xxx driver frees the unsolicited-context object with kfree() without first unlinking it from fcport->unsol_ctx_head, where qla2xxx_process_purls_iocb() put it. The list then holds a freed node: the next list_add_tail() for that fcport writes through freed memory and a later list_del() can corrupt the list or panic. The fix adds the missing list_del() before the free, matching the other free sites. Impact on a storage-attached node is use-after-free memory corruption and a likely panic while FC-NVMe LS responses are failing, taking the node out along with its storage path. Kept separate from the locking bug in the same file (CVE-2026-97527) because the mechanism and the fix differ - one is a missing lock across contexts, this is a missing unlink on one error path - and a node may carry one fix without the other. Nodes without qla2xxx FC HBAs or without FC-NVMe are unaffected.

Who can reach it

Requires the qla2xxx driver with FC-NVMe in use and an LS-reject/error condition on unsolicited LS handling, driven by Fibre Channel fabric traffic. No host login and no tenant-side access reaches this; an unprivileged local user cannot trigger it.

What to do

Move to a stable kernel containing the linked commits and reboot each affected node. As with the sibling qla2xxx fix, a module reload is not realistic where root or dataset storage sits behind the HBA, so budget a drain and reboot per FC-attached node and pick both qla2xxx fixes up in the same window. No configuration-only mitigation.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.