« Volver al listado

CVE-2026-97528

Estado: RecibidaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error

qla_nvme_xmt_ls_rsp() obtains uctx, which was linked into fcport->unsol_ctx_head by qla2xxx_process_purls_iocb() and is still linked when the NVMe transport calls back to transmit the LS response. On the error (out:) path the function frees uctx with kfree() but never removes it from the list. This leaves a freed node in fcport->unsol_ctx_head: the next list_add_tail() for that fcport writes through the freed node, and a subsequent list_del() can corrupt the list or panic.

Leer descripción completaMostrar menos

Unlink uctx with list_del() before kfree() on the error path, matching the other free sites in qla_nvme_release_lsrsp_cmd_kref() and qla2xxx_process_purls_pkt(). qla2x00_rel_sp() in the failure path only returns the SRB to its pool and does not invoke sp->put_fn, so the out: path is the sole free and uctx is always still linked there.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de corrupción de memoria en kernel Linux (qla2xxx) accesible via red adyacente (AV:A). Causa DoS por pánico o corrupción de estructura de datos en procesamiento de respuestas NVMe LS.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97528",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "cbbf1484496aac86038e67ac984949af58009d4b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "a95fc5f1c12bba1dbff72bd2611e7fad0758831b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "c55d649a6cc246c3ccd5d118faea230c46b60f35",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "875386b98857822b77ac7f95bdf367b70af5b78c",
              "lessThan": "e46160a5d4fa59bf4d5f3412b6b5cb79edb967dd",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_nvme.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_nvme.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:02.980",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/a95fc5f1c12bba1dbff72bd2611e7fad0758831b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c55d649a6cc246c3ccd5d118faea230c46b60f35",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cbbf1484496aac86038e67ac984949af58009d4b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e46160a5d4fa59bf4d5f3412b6b5cb79edb967dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error\n\nqla_nvme_xmt_ls_rsp() obtains uctx, which was linked into\nfcport->unsol_ctx_head by qla2xxx_process_purls_iocb() and is still linked\nwhen the NVMe transport calls back to transmit the LS response. On the\nerror (out:) path the function frees uctx with kfree() but never removes\nit from the list. This leaves a freed node in fcport->unsol_ctx_head: the\nnext list_add_tail() for that fcport writes through the freed node, and a\nsubsequent list_del() can corrupt the list or panic.\n\nUnlink uctx with list_del() before kfree() on the error path, matching the\nother free sites in qla_nvme_release_lsrsp_cmd_kref() and\nqla2xxx_process_purls_pkt(). qla2x00_rel_sp() in the failure path only\nreturns the SRB to its pool and does not invoke sp->put_fn, so the out:\npath is the sole free and uctx is always still linked there."
    }
  ],
  "lastModified": "2026-10-03T11:18:01.597",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}