« Volver al listado

CVE-2026-97529

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]

The FC BSG transport allocates job->request via memdup_user() using the exact user-supplied request_len. For FC_BSG_HST_VENDOR, fc_bsg_host_dispatch() only guarantees request_len covers msgcode and vendor_id; it does not account for the vendor_cmd[] flexible array.

qla2xxx then reads the command selector vendor_cmd[0] and, in several sub-handlers, vendor_cmd[1]/[2] or structures overlaid on the vendor command area without verifying request_len. A caller holding CAP_SYS_RAWIO can submit a short request whose vendor_id matches the host, triggering out-of-bounds heap reads (KASAN-detectable, and able to mis-select a command or panic).

Leer descripción completaMostrar menos

Add a central guard in qla2x00_process_vendor_specific() so the selector is always in bounds, restrict the early vendor_cmd[0] read in qla24xx_bsg_request() to sufficiently long vendor messages, and add request_len checks to the sub-handlers that read further: qla24xx_proc_fcp_prio_cfg_cmd(), qla2x00_process_loopback(), qla84xx_reset(), qla84xx_updatefw(), qla2x00_read_optrom(), qla2x00_update_optrom(), qlafx00_mgmt_cmd() and qla28xx_validate_flash_image().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97529",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "01e0e15c8b3b32e006e5cccac10c8b377ac3d803",
              "lessThan": "ef63922d8bdea03de1804af39a6b12212acb1be2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01e0e15c8b3b32e006e5cccac10c8b377ac3d803",
              "lessThan": "740f3458a4798af54aaf8cf63e797d407e8b6d3b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01e0e15c8b3b32e006e5cccac10c8b377ac3d803",
              "lessThan": "f75bff451a2fac5aed82f9641df1e9a42c5a899d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01e0e15c8b3b32e006e5cccac10c8b377ac3d803",
              "lessThan": "4cf38dd9465736141263ebb63375868311a0ec81",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_bsg.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_bsg.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:03.087",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4cf38dd9465736141263ebb63375868311a0ec81",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/740f3458a4798af54aaf8cf63e797d407e8b6d3b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ef63922d8bdea03de1804af39a6b12212acb1be2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f75bff451a2fac5aed82f9641df1e9a42c5a899d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]\n\nThe FC BSG transport allocates job->request via memdup_user() using the\nexact user-supplied request_len. For FC_BSG_HST_VENDOR,\nfc_bsg_host_dispatch() only guarantees request_len covers msgcode and\nvendor_id; it does not account for the vendor_cmd[] flexible array.\n\nqla2xxx then reads the command selector vendor_cmd[0] and, in several\nsub-handlers, vendor_cmd[1]/[2] or structures overlaid on the vendor\ncommand area without verifying request_len. A caller holding\nCAP_SYS_RAWIO can submit a short request whose vendor_id matches the\nhost, triggering out-of-bounds heap reads (KASAN-detectable, and able to\nmis-select a command or panic).\n\nAdd a central guard in qla2x00_process_vendor_specific() so the selector\nis always in bounds, restrict the early vendor_cmd[0] read in\nqla24xx_bsg_request() to sufficiently long vendor messages, and add\nrequest_len checks to the sub-handlers that read further:\nqla24xx_proc_fcp_prio_cfg_cmd(), qla2x00_process_loopback(),\nqla84xx_reset(), qla84xx_updatefw(), qla2x00_read_optrom(),\nqla2x00_update_optrom(), qlafx00_mgmt_cmd() and\nqla28xx_validate_flash_image()."
    }
  ],
  "lastModified": "2026-10-03T11:18:01.733",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}