« Volver al listado

CVE-2026-97535

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size

The VP control IOCB selects its target virtual port by setting one bit in vp_idx_map, a fixed 16-byte (128-bit) array in both vp_ctrl_entry_24xx and vp_ctrl_entry_24xx_ext. qla25xx_ctrlvp_iocb() computes map = (vp_index - 1) / 8 and writes vce->vp_idx_map[map] without checking that map stays within the array.

max_npiv_vports is taken from firmware and only sanitized to a MIN_MULTI_ID_FABRIC-aligned boundary, so it can legitimately be 191 or 255, and qla24xx_control_vp() only rejects vp_index >= max_npiv_vports.

Leer descripción completaMostrar menos

A vp_index above 128 therefore yields map >= 16 and an out-of-bounds write of up to 16 bytes past vp_idx_map, corrupting the trailing IOCB fields (or the adjacent request-ring slot on the 64-byte layout).

Reject a vp_index that cannot be represented in the IOCB bitmap in qla24xx_control_vp(), and add a defensive ARRAY_SIZE() guard in qla25xx_ctrlvp_iocb() before the write. Adapters that report the usual 63 or 127 NPIV vports are unaffected.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97535",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2853192e154b813fe34a6cbee5e34dfef50d29d0",
              "lessThan": "c80a0362a0fe548c15a0324b1f61c04b62bb2174",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2853192e154b813fe34a6cbee5e34dfef50d29d0",
              "lessThan": "48a44e19746eaa70320a3c2571dcb345192fca72",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2853192e154b813fe34a6cbee5e34dfef50d29d0",
              "lessThan": "13354ad251ab009102597a791bc7c4d2265229e1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2853192e154b813fe34a6cbee5e34dfef50d29d0",
              "lessThan": "878613ecb5a36db26859c4fd83daf9283a334fa2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_iocb.c",
            "drivers/scsi/qla2xxx/qla_mid.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_iocb.c",
            "drivers/scsi/qla2xxx/qla_mid.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:03.757",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/13354ad251ab009102597a791bc7c4d2265229e1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/48a44e19746eaa70320a3c2571dcb345192fca72",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/878613ecb5a36db26859c4fd83daf9283a334fa2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c80a0362a0fe548c15a0324b1f61c04b62bb2174",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size\n\nThe VP control IOCB selects its target virtual port by setting one bit\nin vp_idx_map, a fixed 16-byte (128-bit) array in both\nvp_ctrl_entry_24xx and vp_ctrl_entry_24xx_ext. qla25xx_ctrlvp_iocb()\ncomputes map = (vp_index - 1) / 8 and writes vce->vp_idx_map[map]\nwithout checking that map stays within the array.\n\nmax_npiv_vports is taken from firmware and only sanitized to a\nMIN_MULTI_ID_FABRIC-aligned boundary, so it can legitimately be 191 or\n255, and qla24xx_control_vp() only rejects vp_index >= max_npiv_vports.\nA vp_index above 128 therefore yields map >= 16 and an out-of-bounds\nwrite of up to 16 bytes past vp_idx_map, corrupting the trailing IOCB\nfields (or the adjacent request-ring slot on the 64-byte layout).\n\nReject a vp_index that cannot be represented in the IOCB bitmap in\nqla24xx_control_vp(), and add a defensive ARRAY_SIZE() guard in\nqla25xx_ctrlvp_iocb() before the write. Adapters that report the usual\n63 or 127 NPIV vports are unaffected."
    }
  ],
  "lastModified": "2026-10-03T11:18:02.283",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}