CVE-2026-43414
scsi: qla2xxx: Completely fix fcport double free
CVSS Score
9.8
EPSS Score
0.1%
EPSS Percentile
18th
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is called by qla2x00_sp_release(), when kref_put() releases the first and the last reference. qla2x00_els_dcmd_sp_free() frees fcport by calling qla2x00_free_fcport(). Doing it one more time after kref_put() is a bad idea.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | May 8, 2026 |
| Last Updated | May 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new critical vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Linux / Linux
4895009c4bb72f71f2e682f1e7d2c2d96e482087 < d48ea85463f5b34f7b92ea0a13eddf1ab993da7b 4895009c4bb72f71f2e682f1e7d2c2d96e482087 < c0b7da13a04bd70ef6070bfb9ea85f582294560a 7861213201838480dc222634c56fb6db113d010d 3b9d72442adfbc9ddb0f76dd1b03977b3a578b16 ef23850940d9a52c39936d27254824ccf5e9b6bd 6c6bf6cacf9461f8d301cfac4f9c175d80cbcc63 cd10dee1f07a782f5aa05703c55299ca86a85ee4 b03e626bd6d3f0684f56ee1890d70fc9ca991c04 282877633b25d67021a34169c5b5519b1d4ef65e f85af9f1aa5e2f53694a6cbe72010f754b5ff862 9b43d2884b54d415caab48878b526dfe2ae9921b 846fb9f112f618ec6ae181d8dae7961652574774 5.15.154 < 5.16 6.1.84 < 6.2 6.6.24 < 6.7 6.7.12 < 6.8 6.8.3 < 6.9
Linux / Linux
6.9