Database/Kernel, userspace & hypervisor
Linux kernel qla2xxx: unvalidated FC BSG request length causes out-of-bounds heap reads
Impact
The FC BSG transport allocates the request with memdup_user() at exactly the user-supplied request_len, and for FC_BSG_HST_VENDOR it only guarantees that the length covers msgcode and vendor_id - not the vendor_cmd[] flexible array. qla2xxx read vendor_cmd[0] as a command selector, and several sub-handlers read further words or structures overlaid on the vendor command area, without checking the length. A short request with a matching vendor_id yields out-of-bounds heap reads, can mis-select a command (including flash and optrom handlers) and can panic the host. On a GPU node with Fibre Channel attached storage that is an avoidable host crash and a path to leaking adjacent heap contents into a management tool's reply.
Who can reach it
Local user holding CAP_SYS_RAWIO able to issue FC BSG ioctls against the HBA - in practice host root or a storage management agent, not an ordinary tenant pod. No network or fabric access required.
What to do
Run a kernel with the central bounds guard in qla2x00_process_vendor_specific() plus the per-handler request_len checks; four stable backports are linked in the record. That is a drain and reboot of each FC-attached node. Until then, restrict CAP_SYS_RAWIO and the HBA management tooling that uses this interface. The record carries no vendor advisory or fixed firmware version.
References
Related entries
- Linux kernel qla2xxx: FC frame payload aliasing 0xDEADDEAD spins the interrupt handler into a CPU soft lockupCVE-2026-97530 · Linux kernel qla2xxx (continuation IOCB signature poll in interrupt context)Unscored
- Linux qla2xxx: double free and NULL dma_pool use when adapter memory allocation fails at probeCVE-2026-97532 · Linux kernel scsi qla2xxx (qla2x00_mem_alloc error path, dangling pointers)Unscored
- Linux kernel qla2xxx: NPIV virtual-port index above 128 writes past the VP control IOCB bitmapCVE-2026-97535 · Linux kernel qla2xxx (VP_CTRL IOCB vp_idx_map bounds)Unscored
- Linux qla2xxx: NULL dma_free and mismatched bitmap locking in multiqueue queue teardownCVE-2026-97537 · Linux kernel scsi qla2xxx (multiqueue req/rsp queue teardown, qid bitmap locking)Unscored
- Linux kernel io_uring: MSG_TRUNC recv over-advances the provided buffer ringCVE-2026-97618 · Linux kernel io_uring/net (provided buffer ring accounting with MSG_TRUNC)Unscored
- Linux kernel io_uring: deferred write accounting deadlocks a task against filesystem freezeCVE-2026-97619 · Linux kernel io_uring/rw (superblock write accounting released from task_work)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.