GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel qla2xxx: unvalidated FC BSG request length causes out-of-bounds heap reads

UnscoredCVE-2026-97529Kernel, userspace & hypervisorcurated

Impact

The FC BSG transport allocates the request with memdup_user() at exactly the user-supplied request_len, and for FC_BSG_HST_VENDOR it only guarantees that the length covers msgcode and vendor_id - not the vendor_cmd[] flexible array. qla2xxx read vendor_cmd[0] as a command selector, and several sub-handlers read further words or structures overlaid on the vendor command area, without checking the length. A short request with a matching vendor_id yields out-of-bounds heap reads, can mis-select a command (including flash and optrom handlers) and can panic the host. On a GPU node with Fibre Channel attached storage that is an avoidable host crash and a path to leaking adjacent heap contents into a management tool's reply.

Who can reach it

Local user holding CAP_SYS_RAWIO able to issue FC BSG ioctls against the HBA - in practice host root or a storage management agent, not an ordinary tenant pod. No network or fabric access required.

What to do

Run a kernel with the central bounds guard in qla2x00_process_vendor_specific() plus the per-handler request_len checks; four stable backports are linked in the record. That is a drain and reboot of each FC-attached node. Until then, restrict CAP_SYS_RAWIO and the HBA management tooling that uses this interface. The record carries no vendor advisory or fixed firmware version.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.