{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89848","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.770Z","datePublished":"2026-09-16T10:31:22.197Z","dateUpdated":"2026-09-16T14:39:16.899Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:16.899Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Quiesce response IRQ before freeing request queue\n\nqla2xxx_delete_qpair() deletes the request queue before the response\nqueue. qla25xx_delete_req_que() frees the request queue memory\n(kfree(req) in qla25xx_free_req_que()), but the response-queue MSI-X is\nonly released later, in qla25xx_free_rsp_que(). In that window the\nresponse interrupt can still fire, qla2xxx_msix_rsp_q() queues\nqpair->q_work, and qla_do_work() -> qla24xx_process_response_queue()\ndereferences the now-freed rsp->req (LOGINOUT/CT/ELS entries and the\nstatus path), a use-after-free.\n\nThe cancel_work_sync() added for the qpair teardown lives in the\nresponse free path, which runs after the request queue is already freed,\nso it does not protect rsp->req.\n\nRelease the response-queue interrupt and flush qpair->q_work before\ndeleting the request queue, so no late completion can reach the freed\nrequest queue. Clearing have_irq makes the subsequent\nqla25xx_free_rsp_que() skip its free_irq(), and the firmware\nqueue-delete order (request then response) is preserved; the\nrequest-delete mailbox completes on the default vector and is unaffected\nby dropping the qpair response interrupt early."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - qla24xx_process_response_queue() runs from the qla2xxx response-queue MSI-X/work path on firmware-DMAed LOGINOUT/CT/ELS/status IOCBs from Fibre Channel, FCoE, or FCIP traffic; a remote SAN peer can induce those completions without a local syscall, matching sibling CVE-2026-89845 Network scoring of the same teardown window.\nAC:H - The use-after-free requires qla25xx_free_req_que() to kfree the request queue while the response MSI-X is still registered, which occurs only during qpair, NPIV vport, or device teardown, a victim state a fabric attacker cannot initiate.\nPR:N - Response-queue interrupt handling of LOGINOUT/CT/ELS/status completions runs from unauthenticated Fibre Channel firmware IOCBs with no Linux credential or capability check, so a fabric peer needs no account on the victim host.\nUI:N - Response-queue interrupt handling is automatic; concurrent qpair teardown occurs during routine driver remove, NPIV vport deletion, or PCI removal without interactive victim actions such as mounting a filesystem.\nS:U - The use-after-free is inside the host kernel qla2xxx driver and does not cross a VM, IOMMU, or other separate security-authority boundary.\nC:H - After kfree(req), rsp->req remains dangling and qla_get_sp_from_handle() reads req->num_outstanding_cmds and req->outstanding_cmds[]; that request-queue use-after-free enables disclosure of reused heap contents.\nI:H - qla2x00_get_sp_from_handle() writes NULL into the freed outstanding_cmds slot, and subsequent LOGINOUT/CT/ELS completion handling operates on a recycled req/srb object, yielding a kernel write and control-flow hijack primitive.\nA:H - Use-after-free of the request queue from qla_do_work()/qla24xx_process_response_queue produces a kernel oops or panic even when not fully exploited, taking down storage served by the adapter."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/qla2xxx/qla_init.c"],"versions":[{"version":"d74595278f4ab192af66d9e60a9087464638beee","lessThan":"7ac5be2a8609679fc6bbfea881360444a5ce8202","status":"affected","versionType":"git"},{"version":"d74595278f4ab192af66d9e60a9087464638beee","lessThan":"1486cc18be3e2b4c2a730f4a1b0448d009381b3d","status":"affected","versionType":"git"},{"version":"d74595278f4ab192af66d9e60a9087464638beee","lessThan":"10e9f05f7fd0a103886a867ec8afe621fe4b906a","status":"affected","versionType":"git"},{"version":"d74595278f4ab192af66d9e60a9087464638beee","lessThan":"157ca7d1af45f87aa14a286754f19c3f72386988","status":"affected","versionType":"git"},{"version":"d74595278f4ab192af66d9e60a9087464638beee","lessThan":"505753ec2594c6af09a601f0dd60be7d840c1d2d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/qla2xxx/qla_init.c"],"versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7ac5be2a8609679fc6bbfea881360444a5ce8202"},{"url":"https://git.kernel.org/stable/c/1486cc18be3e2b4c2a730f4a1b0448d009381b3d"},{"url":"https://git.kernel.org/stable/c/10e9f05f7fd0a103886a867ec8afe621fe4b906a"},{"url":"https://git.kernel.org/stable/c/157ca7d1af45f87aa14a286754f19c3f72386988"},{"url":"https://git.kernel.org/stable/c/505753ec2594c6af09a601f0dd60be7d840c1d2d"}],"title":"scsi: qla2xxx: Quiesce response IRQ before freeing request queue","x_generator":{"engine":"bippy-1.2.0"}}}}