« Volver al listado

CVE-2026-93242

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb()

qla24xx_process_response_queue() advances ring_ptr past the head IOCB before dispatching, so by the time __qla_consume_iocb() runs, ring_ptr already points at the first continuation IOCB. The function however looped purex->entry_count times starting at ring_ptr. As entry_count includes the head, this consumed one entry too many: it stamped RESPONSE_PROCESSED on the next, unrelated IOCB and advanced the ring past it, silently dropping a legitimate firmware response. The head IOCB's signature was also never marked.

Leer descripción completaMostrar menos

Mark the head processed and account for it, then consume only the entry_count - 1 continuation IOCBs, matching __qla_copy_purex_to_buffer().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93242",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fac2807946c10b9a509b9c348afd442fa823c5f7",
              "lessThan": "a136c311676fd1010b1bde3bcfd410caa2fa040f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fac2807946c10b9a509b9c348afd442fa823c5f7",
              "lessThan": "d841707fafba5f80341b82e8c3a4c24fc5aa5132",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fac2807946c10b9a509b9c348afd442fa823c5f7",
              "lessThan": "6e3f129538c32d0019437197735912308c161843",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fac2807946c10b9a509b9c348afd442fa823c5f7",
              "lessThan": "bd1534d4afab47f13dfc27fff6f59dd859a0ac3a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fac2807946c10b9a509b9c348afd442fa823c5f7",
              "lessThan": "31715d1e1cbf3a37ce3452635c5602f73fd7abd4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fac2807946c10b9a509b9c348afd442fa823c5f7",
              "lessThan": "df86c27cf1ba9d66f737a1fa56479c6e7efafe4e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fac2807946c10b9a509b9c348afd442fa823c5f7",
              "lessThan": "3ba019bdd89d931499d9476456b5d9c7ab7fa753",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_isr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_isr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:20.090",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/31715d1e1cbf3a37ce3452635c5602f73fd7abd4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3ba019bdd89d931499d9476456b5d9c7ab7fa753",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e3f129538c32d0019437197735912308c161843",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a136c311676fd1010b1bde3bcfd410caa2fa040f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bd1534d4afab47f13dfc27fff6f59dd859a0ac3a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d841707fafba5f80341b82e8c3a4c24fc5aa5132",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/df86c27cf1ba9d66f737a1fa56479c6e7efafe4e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb()\n\nqla24xx_process_response_queue() advances ring_ptr past the head IOCB\nbefore dispatching, so by the time __qla_consume_iocb() runs, ring_ptr\nalready points at the first continuation IOCB. The function however\nlooped purex->entry_count times starting at ring_ptr. As entry_count\nincludes the head, this consumed one entry too many: it stamped\nRESPONSE_PROCESSED on the next, unrelated IOCB and advanced the ring\npast it, silently dropping a legitimate firmware response. The head\nIOCB's signature was also never marked.\n\nMark the head processed and account for it, then consume only the\nentry_count - 1 continuation IOCBs, matching __qla_copy_purex_to_buffer()."
    }
  ],
  "lastModified": "2026-09-24T16:17:20.090",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}