Database/Kernel, userspace & hypervisor
Linux kernel qla2xxx: NVMe-FC unsolicited context freed while still linked, leaving a freed node on the list
Impact
On the error path of qla_nvme_xmt_ls_rsp(), the qla2xxx driver frees the unsolicited-context object with kfree() without first unlinking it from fcport->unsol_ctx_head, where qla2xxx_process_purls_iocb() put it. The list then holds a freed node: the next list_add_tail() for that fcport writes through freed memory and a later list_del() can corrupt the list or panic. The fix adds the missing list_del() before the free, matching the other free sites. Impact on a storage-attached node is use-after-free memory corruption and a likely panic while FC-NVMe LS responses are failing, taking the node out along with its storage path. Kept separate from the locking bug in the same file (CVE-2026-97527) because the mechanism and the fix differ - one is a missing lock across contexts, this is a missing unlink on one error path - and a node may carry one fix without the other. Nodes without qla2xxx FC HBAs or without FC-NVMe are unaffected.
Who can reach it
Requires the qla2xxx driver with FC-NVMe in use and an LS-reject/error condition on unsolicited LS handling, driven by Fibre Channel fabric traffic. No host login and no tenant-side access reaches this; an unprivileged local user cannot trigger it.
What to do
Move to a stable kernel containing the linked commits and reboot each affected node. As with the sibling qla2xxx fix, a module reload is not realistic where root or dataset storage sits behind the HBA, so budget a drain and reboot per FC-attached node and pick both qla2xxx fixes up in the same window. No configuration-only mitigation.
References
Related entries
- Linux kernel mlx5_core representor TC path + net/sched tc extension: The TC_SKB_EXT skb extension is not zeroedCVE-2021-47136 · Linux kernel mlx5_core representor TC path + net/sched tc extensionHigh
- Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLSCVE-2025-38608 · Linux kernel (net/tls)High
- Linux kernel libceph: truncated monitor reply decodes stale bytes from the reused bufferCVE-2026-68433 · Linux kernel libceph (MON_GET_VERSION_REPLY decode bound)High
- sudo: intercept policy checks skipped for execveat, letting allowed users run denied commandsCVE-2026-82474 · sudo (ptrace-based intercept mode, execveat/fexecve path)High
- Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVMCVE-2024-50115 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel arm_ffa: unvalidated notification layout drives out-of-bounds read of the shared RX bufferCVE-2026-64081 · Linux kernel arm_ffa (Arm FF-A framework notification parsing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.