Use-after-free in Linux kernel - CVE-2026-97536
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to use-after-free in the qla2xxx response queue work handling when tearing down a response queue with queued response work. A remote attacker can exploit the race condition during queue teardown to compromise confidentiality, integrity, and availability.
The condition is especially likely during full adapter teardown, which forces pending work to run after queue pairs have been freed.