Database/Kernel, userspace & hypervisor
Linux qla2xxx: pending qpair work runs after response queue teardown, causing use-after-free
Impact
The MSI-X response-queue handler schedules qla_do_work() on the driver workqueue, but queue-pair teardown calls free_irq() and then frees the response queue and qpair without cancelling work already queued. free_irq() waits only for running hardirq handlers, so a still-pending work item dereferences the freed qpair and response queue. This is most likely during full adapter teardown, where destroy_workqueue() forces pending work to run after the queue pairs are gone - meaning a driver unload or adapter reset on a storage-attached node can corrupt kernel memory. This is a distinct bug from the vport re-registration use-after-free in the same driver and has its own fix. Resolved by adding cancel_work_sync() in qla25xx_free_rsp_que() after free_irq() and before the memory is released.
Who can reach it
Adjacent-network fabric traffic driving response-queue interrupts, racing a local queue-pair or adapter teardown. High complexity; requires QLogic FC hardware on the node. No authentication is involved.
What to do
Take the stable kernel update carrying the cancel_work_sync() fix (three stable commits referenced). Kernel update and reboot per affected node; in the meantime avoid unnecessary qla2xxx unloads and adapter resets on production storage nodes. Nodes without QLogic FC HBAs are unaffected.
References
Related entries
- Linux nvme: sparse NSID gaps make namespace scan iterate billions of times, causing soft lockupCVE-2026-98056 · Linux kernel nvme core (nvme_scan_ns_list stale-namespace removal)High
- Linux kernel (overlayfs, Ubuntu patch): OverlayFS file-capability privilege escalationCVE-2021-3493 · Linux kernel (overlayfs, Ubuntu patch)High
- OpenSSL: X.400 address type confusion in X.509 GeneralNameCVE-2023-0286 · OpenSSLHigh
- Linux kernel (net/sched tcindex): Use-after-free in the tcindex traffic-control filter - local rootCVE-2023-1829 · Linux kernel (net/sched tcindex)High
- QEMU: missing iov bounds check in the virtio-snd input callback gives a guest a heap out-of-bounds writeCVE-2026-3195 · QEMU virtio-snd device (virtio_snd_pcm_in_cb input callback)High
- Linux kernel (arch/x86/kvm/svm): After a CPU offline/online cycle, KVM's ASID generation counter is reset in a way thatCVE-2026-68093 · Linux kernel (arch/x86/kvm/svm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.