GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux qla2xxx: pending qpair work runs after response queue teardown, causing use-after-free

CVSS 7.5CVE-2026-97536Kernel, userspace & hypervisorcurated

Impact

The MSI-X response-queue handler schedules qla_do_work() on the driver workqueue, but queue-pair teardown calls free_irq() and then frees the response queue and qpair without cancelling work already queued. free_irq() waits only for running hardirq handlers, so a still-pending work item dereferences the freed qpair and response queue. This is most likely during full adapter teardown, where destroy_workqueue() forces pending work to run after the queue pairs are gone - meaning a driver unload or adapter reset on a storage-attached node can corrupt kernel memory. This is a distinct bug from the vport re-registration use-after-free in the same driver and has its own fix. Resolved by adding cancel_work_sync() in qla25xx_free_rsp_que() after free_irq() and before the memory is released.

Who can reach it

Adjacent-network fabric traffic driving response-queue interrupts, racing a local queue-pair or adapter teardown. High complexity; requires QLogic FC hardware on the node. No authentication is involved.

What to do

Take the stable kernel update carrying the cancel_work_sync() fix (three stable commits referenced). Kernel update and reboot per affected node; in the meantime avoid unnecessary qla2xxx unloads and adapter resets on production storage nodes. Nodes without QLogic FC HBAs are unaffected.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.