CVE-2026-97527

Source
https://cve.org/CVERecord?id=CVE-2026-97527
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97527.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97527
Downstream
Published
2026-09-25T10:21:29Z
Modified
2026-09-26T03:48:29Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock

The fcport->unsol_ctx_head list is modified from several contexts without a common lock. Entries are added in qla2xxx_process_purls_iocb() from the response queue ISR (under the qpair qp_lock), while they are removed from qla2xxx_process_purls_pkt() (DPC/purex worker), qla_nvme_xmt_ls_rsp() (NVMe-FC transport callback) and qla_nvme_release_lsrsp_cmd_kref() (SRB completion). The qpair qp_lock cannot serialize this per-fcport list since multiqueue adapters add entries through different qpairs, so a concurrent add and delete (or two concurrent deletes) can corrupt the list pointers.

Introduce a dedicated per-fcport spinlock, unsol_ctx_lock, initialized in qla2x00_alloc_fcport(), and take it around every list_add_tail()/list_del() on unsol_ctx_head. The add nests under the existing qp_lock; no delete path takes qp_lock, so the lock order is consistent and deadlock free.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97527.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
875386b98857822b77ac7f95bdf367b70af5b78c
Fixed
b211d138cad86f749826d6132db6388eded992d8
Fixed
4d8ad6bc8cc5eff1870cef00a0d611f38f8b6bd0
Fixed
76da0c43c63eb0496649e372ac64466364d0fe7d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97527.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97527.json"