SB20260925128 - Off-by-one in Linux kernel scsi qla2xxx driver
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Off-by-one (CVE-ID: CVE-2026-93242)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause legitimate firmware responses to be dropped.
The vulnerability exists due to an off-by-one error in __qla_consume_iocb() in the qla2xxx response queue handler when processing response queue IOCBs. A local user can trigger response queue processing to consume an unrelated IOCB and cause legitimate firmware responses to be dropped.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/31715d1e1cbf3a37ce3452635c5602f73fd7abd4
- https://git.kernel.org/stable/c/3ba019bdd89d931499d9476456b5d9c7ab7fa753
- https://git.kernel.org/stable/c/6e3f129538c32d0019437197735912308c161843
- https://git.kernel.org/stable/c/a136c311676fd1010b1bde3bcfd410caa2fa040f
- https://git.kernel.org/stable/c/bd1534d4afab47f13dfc27fff6f59dd859a0ac3a
- https://git.kernel.org/stable/c/d841707fafba5f80341b82e8c3a4c24fc5aa5132
- https://git.kernel.org/stable/c/df86c27cf1ba9d66f737a1fa56479c6e7efafe4e