Database/Kernel, userspace & hypervisor
Linux qla2xxx: double free and NULL dma_pool use when adapter memory allocation fails at probe
Impact
When qla2x00_mem_alloc() fails, its error labels freed adapter members (elsrej.c, purex_dma_pool, flt, sfp_data, loop_id_map, async_pd, sf_init_cb, ex_init_cb, npiv_info) without clearing the pointers, and qla2x00_probe_one() then called qla2x00_mem_free(), which freed them a second time. For the DMA pool members it also called dma_pool_free() against ha->s_dma_pool after that pool had been destroyed and set to NULL, dereferencing a NULL pool. The practical outcome is a kernel crash or heap corruption during Fibre Channel HBA probe on hosts that use QLogic adapters for their SAN or shared scratch storage - an availability and integrity problem at boot or driver load, not something a tenant reaches. No CVSS score is provided.
Who can reach it
Not attacker-reachable in any way the record describes: the path requires an allocation failure inside qla2x00_mem_alloc(), i.e. memory exhaustion during device probe or driver load. Local root at most.
What to do
Roll a stable kernel that clears the freed pointers and DMA handles in the error labels (three stable commits listed) and reboot the affected storage-attached hosts. Treat it as routine kernel hygiene rather than an emergency window. No distro fixed version appears in the record.
References
Related entries
- Linux qla2xxx: NULL dma_free and mismatched bitmap locking in multiqueue queue teardownCVE-2026-97537 · Linux kernel scsi qla2xxx (multiqueue req/rsp queue teardown, qid bitmap locking)Unscored
- Linux LIO iSCSI target: LUN_RESET on a WRITE_PENDING command deadlocks the target worker threadCVE-2026-97951 · Linux kernel SCSI target iSCSI frontend (aborted WRITE_PENDING dataout handling)Unscored
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeCVE-2026-98163 · Linux kernel cgroup task iterator (css_task_iter_next over dying_tasks)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992 · VMware ESXi (OpenSLP)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.