AZL-104723

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104723.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-104723
Upstream
Published
2026-09-25T11:17:03Z
Modified
2026-09-26T14:15:59Z
Summary
CVE-2026-97537 affecting package kernel 6.6.157.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking

qla25xx_free_req_que() and qla25xx_free_rsp_que() have two pre-existing bugs exposed on the error path of qla25xx_create_{req,rsp}_que():

  1. When dma_alloc_coherent() fails during queue creation, the error path calls the free function with req->ring / rsp->ring still NULL (from kzalloc). The unconditional dma_free_coherent() with a NULL cpu_addr is undefined behavior and can panic.

  2. The free functions clear req_qid_map / rsp_qid_map under vport_lock, but the create functions protect the same bitmaps with mq_lock. This provides no mutual exclusion. Additionally, the create error path clears the bit and releases mq_lock before calling the free function, creating a window where another thread can allocate the same que_id and have its ha->req_q_map entry clobbered by the subsequent lockless NULL assignment in the free function.

Fix by:

  • Guarding dma_free_coherent() with a NULL check on the ring pointer.

  • Using mq_lock (the lock held by all creators) in the free functions to atomically NULL the map entry and clear the bitmap bit.

  • Removing the now-redundant clear_bit blocks from the create error paths since the free functions handle it atomically.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
6.6.157.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104723.json"