SB2026091796 - Use-after-free in Linux kernel scsi qla2xxx driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-89861)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to use-after-free in qla24xx_report_id_acquisition() in the qla2xxx SCSI driver when a virtual port is concurrently deallocated after it is found in the virtual port list. A remote attacker can trigger the race condition to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/267533b28ddf2c9223d30ad7e6960fa9e936428e
- https://git.kernel.org/stable/c/47272152a13d202d98496208f9bf382c1cf4d4fb
- https://git.kernel.org/stable/c/4b7f0a95bfeb1d3673da4c29bbe9872a61bc1a69
- https://git.kernel.org/stable/c/793cedee296fd819bfadc2a7ec4d52faf9c09a0a
- https://git.kernel.org/stable/c/d09ef32af1e05d79f29b460521a20bc4e6fd2ecf
- https://git.kernel.org/stable/c/d556f899964d184e6cb788f3fa9dcddcafe1ab2d
- https://git.kernel.org/stable/c/f6b3bcc7cb2f4c37464958b9fd97dc7f185ea297
- https://git.kernel.org/stable/c/f8d2eb510c063a8ca79a5dc766a4303d3925fe83