CVE-2026-43414
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Completely fix fcport double free
In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is called by qla2x00_sp_release(), when kref_put() releases the first and the last reference.
qla2x00_els_dcmd_sp_free() frees fcport by calling qla2x00_free_fcport(). Doing it one more time after kref_put() is a bad idea.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.55%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto secundario
T1499.004Application or System Exploitationimpact65 %
Vector CVSS AV:N/AC:L/PR:N/UI:N indica acceso remoto sin privilegios (T1190). Double-free en kernel SCSI permite ejecución de código remoto (T1059) y denegación de servicio (T1499.004) por corrupción de memoria.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-415
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-43414",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4895009c4bb72f71f2e682f1e7d2c2d96e482087",
"lessThan": "d48ea85463f5b34f7b92ea0a13eddf1ab993da7b",
"versionType": "git"
},
{
"status": "affected",
"version": "4895009c4bb72f71f2e682f1e7d2c2d96e482087",
"lessThan": "c0b7da13a04bd70ef6070bfb9ea85f582294560a",
"versionType": "git"
},
{
"status": "affected",
"version": "7861213201838480dc222634c56fb6db113d010d",
"versionType": "git"
},
{
"status": "affected",
"version": "3b9d72442adfbc9ddb0f76dd1b03977b3a578b16",
"versionType": "git"
},
{
"status": "affected",
"version": "ef23850940d9a52c39936d27254824ccf5e9b6bd",
"versionType": "git"
},
{
"status": "affected",
"version": "6c6bf6cacf9461f8d301cfac4f9c175d80cbcc63",
"versionType": "git"
},
{
"status": "affected",
"version": "cd10dee1f07a782f5aa05703c55299ca86a85ee4",
"versionType": "git"
},
{
"status": "affected",
"version": "b03e626bd6d3f0684f56ee1890d70fc9ca991c04",
"versionType": "git"
},
{
"status": "affected",
"version": "282877633b25d67021a34169c5b5519b1d4ef65e",
"versionType": "git"
},
{
"status": "affected",
"version": "f85af9f1aa5e2f53694a6cbe72010f754b5ff862",
"versionType": "git"
},
{
"status": "affected",
"version": "9b43d2884b54d415caab48878b526dfe2ae9921b",
"versionType": "git"
},
{
"status": "affected",
"version": "846fb9f112f618ec6ae181d8dae7961652574774",
"versionType": "git"
},
{
"status": "affected",
"version": "5.15.154",
"lessThan": "5.16",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.84",
"lessThan": "6.2",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.24",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.7.12",
"lessThan": "6.8",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.8.3",
"lessThan": "6.9",
"versionType": "semver"
}
],
"programFiles": [
"drivers/scsi/qla2xxx/qla_iocb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.19.9",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/scsi/qla2xxx/qla_iocb.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-08T15:16:53.353",
"references": [
{
"url": "https://git.kernel.org/stable/c/c0b7da13a04bd70ef6070bfb9ea85f582294560a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d48ea85463f5b34f7b92ea0a13eddf1ab993da7b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-415"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Completely fix fcport double free\n\nIn qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free().\nWhen an error happens, this function is called by qla2x00_sp_release(),\nwhen kref_put() releases the first and the last reference.\n\nqla2x00_els_dcmd_sp_free() frees fcport by calling qla2x00_free_fcport().\nDoing it one more time after kref_put() is a bad idea."
}
],
"lastModified": "2026-07-08T21:23:03.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21EE109E-592F-4A01-B5D2-F078967481BA",
"versionEndExcluding": "5.16",
"versionStartIncluding": "5.15.154"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E945D81E-D8F5-4962-8003-F5DA3F1FABE3",
"versionEndExcluding": "6.2",
"versionStartIncluding": "6.1.84"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F4D74DB-5E7E-416A-BE8D-4ED1E2EE5D07",
"versionEndExcluding": "6.7",
"versionStartIncluding": "6.6.24"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6A2C3EC-DA7B-4144-8BAF-2DBB7E8CE4C7",
"versionEndExcluding": "6.8",
"versionStartIncluding": "6.7.12"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9974CA02-5BD5-4DE2-9DC2-46DDF0748BB5",
"versionEndExcluding": "6.9",
"versionStartIncluding": "6.8.3"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A794A9A0-D396-422A-9095-DAE3BFB4BC47",
"versionEndExcluding": "6.19.9",
"versionStartIncluding": "6.9.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.9:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F2A4A3D-068A-4CF2-A09F-9C7937DDB0A5"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DF73CB2A-DFFD-46FB-9BFE-AA394F27EA37"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52048DDA-FC5A-4363-95A0-A6357B4D7F8C"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A06B2CCF-3F43-4FA9-8773-C83C3F5764B2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F850DCEC-E08B-4317-A33B-D2DCF39F601B"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91326417-E981-482E-A5A3-28BC1327521B"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.9:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DAECDCD8-F556-4606-8D7B-5C6D47A501F2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}