« Volver al listado

CVE-2026-89842

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started

qla_nvme_xmt_ls_rsp() bails out to the out: label when firmware is not started (!ha->flags.fw_started), but the out: path unconditionally calls qla_nvme_ls_reject_iocb(), which ends in qla2x00_start_iocbs() and an unconditional doorbell write to the request queue in-pointer register. This rings the firmware doorbell and queues an IOCB that stopped or resetting firmware cannot consume, and touches MMIO during the reset/EEH window where fw_started is also clear.

Only emit the LS reject IOCB (and ring the doorbell) when fw_started is set; otherwise just clean up and return.

Leer descripción completaMostrar menos

The post-allocation failure cases (SRB alloc / qla2x00_start_sp() failure) run with firmware started and still send the reject. Apply the same guard to the reject emission in qla2xxx_process_purls_pkt().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89842",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "2935b730211c5c1433aa6101fa3b55df2b63869a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "7c1fc75dd3fb6b6414508fbdf7aeed0d757c9120",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "ac4b019ac07844d3f67ea5e48b1d982b2170d1a7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "e9bfb56e2c1bda49d3c5442d824569d71eec07e2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "f7e46ebffc5781aab3f1f5a5d4350addbb5833f4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_nvme.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_nvme.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:51.040",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2935b730211c5c1433aa6101fa3b55df2b63869a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7c1fc75dd3fb6b6414508fbdf7aeed0d757c9120",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ac4b019ac07844d3f67ea5e48b1d982b2170d1a7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e9bfb56e2c1bda49d3c5442d824569d71eec07e2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f7e46ebffc5781aab3f1f5a5d4350addbb5833f4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started\n\nqla_nvme_xmt_ls_rsp() bails out to the out: label when firmware is not\nstarted (!ha->flags.fw_started), but the out: path unconditionally calls\nqla_nvme_ls_reject_iocb(), which ends in qla2x00_start_iocbs() and an\nunconditional doorbell write to the request queue in-pointer register.\nThis rings the firmware doorbell and queues an IOCB that stopped or\nresetting firmware cannot consume, and touches MMIO during the reset/EEH\nwindow where fw_started is also clear.\n\nOnly emit the LS reject IOCB (and ring the doorbell) when fw_started is\nset; otherwise just clean up and return. The post-allocation failure\ncases (SRB alloc / qla2x00_start_sp() failure) run with firmware started\nand still send the reject. Apply the same guard to the reject emission\nin qla2xxx_process_purls_pkt()."
    }
  ],
  "lastModified": "2026-09-16T11:16:51.040",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}