Database/Kernel, userspace & hypervisor
Linux kernel qla2xxx: NPIV virtual-port index above 128 writes past the VP control IOCB bitmap
Impact
The VP control IOCB selects its target virtual port by setting one bit in vp_idx_map, a fixed 16-byte (128-bit) array. qla25xx_ctrlvp_iocb() computed the byte index as (vp_index - 1) / 8 and wrote it without checking the array bound, while qla24xx_control_vp() only rejected vp_index >= max_npiv_vports - a value taken from firmware that can legitimately be 191 or 255. A vp_index above 128 therefore writes up to 16 bytes past the bitmap, corrupting the trailing IOCB fields or, on the 64-byte layout, the adjacent request-ring slot. The commit is explicit that adapters reporting the usual 63 or 127 NPIV vports are unaffected, so for most fleets this is a latent bug conditional on firmware that advertises a large NPIV limit.
Who can reach it
Local privileged configuration of NPIV virtual ports on an HBA whose firmware reports more than 128 NPIV vports - host root or the storage provisioning agent. Not tenant reachable and not triggered from the fabric.
What to do
Run a kernel with the vp_index rejection in qla24xx_control_vp() and the ARRAY_SIZE() guard in qla25xx_ctrlvp_iocb(); four stable backports are linked in the record. That is a drain and reboot per affected node. Before scheduling anything, check what max_npiv_vports your HBA firmware actually reports - at 63 or 127 you are not exposed and this can ride along with your next routine kernel update.
References
Related entries
- Linux qla2xxx: NULL dma_free and mismatched bitmap locking in multiqueue queue teardownCVE-2026-97537 · Linux kernel scsi qla2xxx (multiqueue req/rsp queue teardown, qid bitmap locking)Unscored
- Linux kernel io_uring: MSG_TRUNC recv over-advances the provided buffer ringCVE-2026-97618 · Linux kernel io_uring/net (provided buffer ring accounting with MSG_TRUNC)Unscored
- Linux kernel io_uring: deferred write accounting deadlocks a task against filesystem freezeCVE-2026-97619 · Linux kernel io_uring/rw (superblock write accounting released from task_work)Unscored
- Linux kernel x86/mm: pmd_modify() drops the dirty bit, losing written data on PMD-mapped THPCVE-2026-97945 · Linux kernel x86/mm pmd_modify() (hardware dirty bit dropped on PMD-mapped THP)Unscored
- Linux kernel powerpc/eeh: recursive locking hangs the EEH handler during PCI error recoveryCVE-2026-97948 · Linux kernel powerpc/eeh (recursive pci_rescan_remove_lock in eeh_rmv_device)Unscored
- Linux LIO iSCSI target: LUN_RESET on a WRITE_PENDING command deadlocks the target worker threadCVE-2026-97951 · Linux kernel SCSI target iSCSI frontend (aborted WRITE_PENDING dataout handling)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.