GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux qla2xxx: dying NPIV vport re-inserted into host_map during report ID acquisition, causing use-after-free

CVSS 7.5CVE-2026-97531Kernel, userspace & hypervisorcurated

Impact

During NPIV vport teardown there is a window where qla24xx_report_id_acquisition() can still find the vport on vp_list and call qla_update_host_map(), re-inserting the dying vport into the host_map btree. Nothing removes that entry afterwards, so once scsi_host_put() frees the vha a later host_map lookup dereferences freed memory. On a storage-attached node this is kernel memory corruption reachable from Fibre Channel fabric events rather than from any tenant workload - the trigger is a fabric ID-acquisition event racing a vport delete. The practical exposure is limited to fleets using QLogic FC HBAs with NPIV vports, but on those nodes the outcome is a kernel crash or worse on a host that carries live storage paths. Fixed by skipping vports with VPORT_DELETE set before taking the reference.

Who can reach it

Adjacent-network via the Fibre Channel fabric, combined with a concurrent NPIV vport deletion on the host. High complexity race; no host authentication involved. Not reachable at all on nodes without qla2xxx HBAs using NPIV.

What to do

Take the stable kernel update carrying the VPORT_DELETE guard (three stable commits referenced). Requires a kernel update and reboot per affected storage-attached node; the qla2xxx module cannot be swapped under active FC paths. Nodes with no QLogic FC HBA need no action.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.