SB20260928406 - Use-after-free in Linux kernel scsi qla2xxx driver
Published: September 28, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-97536)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to use-after-free in the qla2xxx response queue work handling when tearing down a response queue with queued response work. A remote attacker can exploit the race condition during queue teardown to compromise confidentiality, integrity, and availability.
The condition is especially likely during full adapter teardown, which forces pending work to run after queue pairs have been freed.
Remediation
Install update from vendor's website.