SB20260917122 - Use-after-free in Linux kernel scsi qla2xxx driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-89847)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a use-after-free in qla2x00_async_iocb_timeout() in the qla2xxx SCSI driver when an async IOCB timeout races with response interrupt completion. A remote attacker can trigger the race condition to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6e217a9482eabbd8b29847be334c74cf468d3544
- https://git.kernel.org/stable/c/71a7b6e3c7f121439f51a058e53d4a8e05b63dec
- https://git.kernel.org/stable/c/7257b5e1fb6c9387714f66e01b79ec82b717eede
- https://git.kernel.org/stable/c/845d4abd92cd2f97551356c8b281ad6e197acb07
- https://git.kernel.org/stable/c/9fa1d71233a82416492d9c9de9756ebe140fe714
- https://git.kernel.org/stable/c/bb45bc4bd53c95a7bf6f782577b5ede94c0f8aa8
- https://git.kernel.org/stable/c/d6d856c722f40f0694ff755208552e658db6dd42
- https://git.kernel.org/stable/c/f5b660e0b0d9190d8853c795c2522cc5f8c93003