Database/Kernel, userspace & hypervisor
Linux qla2xxx: dying NPIV vport re-inserted into host_map during report ID acquisition, causing use-after-free
Impact
During NPIV vport teardown there is a window where qla24xx_report_id_acquisition() can still find the vport on vp_list and call qla_update_host_map(), re-inserting the dying vport into the host_map btree. Nothing removes that entry afterwards, so once scsi_host_put() frees the vha a later host_map lookup dereferences freed memory. On a storage-attached node this is kernel memory corruption reachable from Fibre Channel fabric events rather than from any tenant workload - the trigger is a fabric ID-acquisition event racing a vport delete. The practical exposure is limited to fleets using QLogic FC HBAs with NPIV vports, but on those nodes the outcome is a kernel crash or worse on a host that carries live storage paths. Fixed by skipping vports with VPORT_DELETE set before taking the reference.
Who can reach it
Adjacent-network via the Fibre Channel fabric, combined with a concurrent NPIV vport deletion on the host. High complexity race; no host authentication involved. Not reachable at all on nodes without qla2xxx HBAs using NPIV.
What to do
Take the stable kernel update carrying the VPORT_DELETE guard (three stable commits referenced). Requires a kernel update and reboot per affected storage-attached node; the qla2xxx module cannot be swapped under active FC paths. Nodes with no QLogic FC HBA need no action.
References
Related entries
- Linux qla2xxx: pending qpair work runs after response queue teardown, causing use-after-freeCVE-2026-97536 · Linux kernel scsi/qla2xxx (queue pair teardown, qla25xx_free_rsp_que)High
- Linux nvme: sparse NSID gaps make namespace scan iterate billions of times, causing soft lockupCVE-2026-98056 · Linux kernel nvme core (nvme_scan_ns_list stale-namespace removal)High
- Linux kernel (overlayfs, Ubuntu patch): OverlayFS file-capability privilege escalationCVE-2021-3493 · Linux kernel (overlayfs, Ubuntu patch)High
- OpenSSL: X.400 address type confusion in X.509 GeneralNameCVE-2023-0286 · OpenSSLHigh
- Linux kernel (net/sched tcindex): Use-after-free in the tcindex traffic-control filter - local rootCVE-2023-1829 · Linux kernel (net/sched tcindex)High
- QEMU: missing iov bounds check in the virtio-snd input callback gives a guest a heap out-of-bounds writeCVE-2026-3195 · QEMU virtio-snd device (virtio_snd_pcm_in_cb input callback)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.