๐Ÿ” CVE Alert

CVE-2026-89856

UNKNOWN 0.0

scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and ha->max_qpairs are u8. Deriving the queue count as "ha->max_req_queues = ha->msix_count - 1" therefore truncates: a board (or a misconfigured/malicious hot-plugged device) advertising 257 MSI-X vectors yields msix_count - 1 == 256, which truncates to 0. An MSI-X count of 1 zeroes it as well, and in target mode the subsequent "ha->max_req_queues--" then underflows 0 to 255. When the count is 0, qla2x00_alloc_queues() calls kzalloc_objs(struct req_que *, 0), which returns ZERO_SIZE_PTR. That is not NULL, so the allocation check passes and the following "ha->req_q_map[0] = req" dereferences ZERO_SIZE_PTR, corrupting memory or crashing the kernel. Add qla_calc_queue_count() to clamp the derived value into [1, QLA_MAX_QUEUES - 1] so it always fits in u8 and is never zero, and use it at all three derivation sites (qla25xx_iospace_config(), qla83xx_iospace_config() and qla24xx_enable_msix()). Also guard the target-mode decrement so it cannot reintroduce a zero (which would in turn underflow max_qpairs).

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d74595278f4ab192af66d9e60a9087464638beee < cf623d32761b00f221a9cfded3303d56e84b429d d74595278f4ab192af66d9e60a9087464638beee < 9eeddbeaa896f39d943644b16d83a6ad0ceab255 d74595278f4ab192af66d9e60a9087464638beee < 802068b9b683b8008fcccbf6e9ad133e597ec87c d74595278f4ab192af66d9e60a9087464638beee < e80adfeac61b4d5db7ffe0f5af43999c33a4145e d74595278f4ab192af66d9e60a9087464638beee < 2efe50b2da829909023de4a2eb87badb7cfa53cc d74595278f4ab192af66d9e60a9087464638beee < 7a448f5ed0b283dbde4e9183dd1e98c221432dab d74595278f4ab192af66d9e60a9087464638beee < 33c77254e6e91f37c72c7fad4051777452b10de8 d74595278f4ab192af66d9e60a9087464638beee < ebfd35c64433821bd5619a6d07ccc2df8b5b1de3
Linux / Linux
4.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/cf623d32761b00f221a9cfded3303d56e84b429d git.kernel.org: https://git.kernel.org/stable/c/9eeddbeaa896f39d943644b16d83a6ad0ceab255 git.kernel.org: https://git.kernel.org/stable/c/802068b9b683b8008fcccbf6e9ad133e597ec87c git.kernel.org: https://git.kernel.org/stable/c/e80adfeac61b4d5db7ffe0f5af43999c33a4145e git.kernel.org: https://git.kernel.org/stable/c/2efe50b2da829909023de4a2eb87badb7cfa53cc git.kernel.org: https://git.kernel.org/stable/c/7a448f5ed0b283dbde4e9183dd1e98c221432dab git.kernel.org: https://git.kernel.org/stable/c/33c77254e6e91f37c72c7fad4051777452b10de8 git.kernel.org: https://git.kernel.org/stable/c/ebfd35c64433821bd5619a6d07ccc2df8b5b1de3