GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux qla2xxx: double free and NULL dma_pool use when adapter memory allocation fails at probe

UnscoredCVE-2026-97532Kernel, userspace & hypervisorcurated

Impact

When qla2x00_mem_alloc() fails, its error labels freed adapter members (elsrej.c, purex_dma_pool, flt, sfp_data, loop_id_map, async_pd, sf_init_cb, ex_init_cb, npiv_info) without clearing the pointers, and qla2x00_probe_one() then called qla2x00_mem_free(), which freed them a second time. For the DMA pool members it also called dma_pool_free() against ha->s_dma_pool after that pool had been destroyed and set to NULL, dereferencing a NULL pool. The practical outcome is a kernel crash or heap corruption during Fibre Channel HBA probe on hosts that use QLogic adapters for their SAN or shared scratch storage - an availability and integrity problem at boot or driver load, not something a tenant reaches. No CVSS score is provided.

Who can reach it

Not attacker-reachable in any way the record describes: the path requires an allocation failure inside qla2x00_mem_alloc(), i.e. memory exhaustion during device probe or driver load. Local root at most.

What to do

Roll a stable kernel that clears the freed pointers and DMA handles in the error labels (three stable commits listed) and reboot the affected storage-attached hosts. Treat it as routine kernel hygiene rather than an emergency window. No distro fixed version appears in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.