๐Ÿ” CVE Alert

CVE-2026-97529

UNKNOWN 0.0

scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] The FC BSG transport allocates job->request via memdup_user() using the exact user-supplied request_len. For FC_BSG_HST_VENDOR, fc_bsg_host_dispatch() only guarantees request_len covers msgcode and vendor_id; it does not account for the vendor_cmd[] flexible array. qla2xxx then reads the command selector vendor_cmd[0] and, in several sub-handlers, vendor_cmd[1]/[2] or structures overlaid on the vendor command area without verifying request_len. A caller holding CAP_SYS_RAWIO can submit a short request whose vendor_id matches the host, triggering out-of-bounds heap reads (KASAN-detectable, and able to mis-select a command or panic). Add a central guard in qla2x00_process_vendor_specific() so the selector is always in bounds, restrict the early vendor_cmd[0] read in qla24xx_bsg_request() to sufficiently long vendor messages, and add request_len checks to the sub-handlers that read further: qla24xx_proc_fcp_prio_cfg_cmd(), qla2x00_process_loopback(), qla84xx_reset(), qla84xx_updatefw(), qla2x00_read_optrom(), qla2x00_update_optrom(), qlafx00_mgmt_cmd() and qla28xx_validate_flash_image().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
01e0e15c8b3b32e006e5cccac10c8b377ac3d803 < 740f3458a4798af54aaf8cf63e797d407e8b6d3b 01e0e15c8b3b32e006e5cccac10c8b377ac3d803 < f75bff451a2fac5aed82f9641df1e9a42c5a899d 01e0e15c8b3b32e006e5cccac10c8b377ac3d803 < 4cf38dd9465736141263ebb63375868311a0ec81
Linux / Linux
4.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/740f3458a4798af54aaf8cf63e797d407e8b6d3b git.kernel.org: https://git.kernel.org/stable/c/f75bff451a2fac5aed82f9641df1e9a42c5a899d git.kernel.org: https://git.kernel.org/stable/c/4cf38dd9465736141263ebb63375868311a0ec81