← All Advisories

CVE-2026-97529

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97529

Key Details

CVECVE-2026-97529
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]

The FC BSG transport allocates job->request via memdup_user() using the

exact user-supplied request_len. For FC_BSG_HST_VENDOR,

fc_bsg_host_dispatch() only guarantees request_len covers msgcode and

vendor_id; it does not account for the vendor_cmd[] flexible array.

qla2xxx then reads the command selector vendor_cmd[0] and, in several

sub-handlers, vendor_cmd[1]/[2] or structures overlaid on the vendor

command area without verifying request_len. A caller holding

CAP_SYS_RAWIO can submit a short request whose vendor_id matches the

host, triggering out-of-bounds heap reads (KASAN-detectable, and able to

mis-select a command or panic).

Add a central guard in qla2x00_process_vendor_specific() so the selector

is always in bounds, restrict the early vendor_cmd[0] read in

qla24xx_bsg_request() to sufficiently long vendor messages, and add

request_len checks to the sub-handlers that read further:

qla24xx_proc_fcp_prio_cfg_cmd(), qla2x00_process_loopback(),

qla84xx_reset(), qla84xx_updatefw(), qla2x00_read_optrom(),

qla2x00_update_optrom(), qlafx00_mgmt_cmd() and

qla28xx_validate_flash_image(). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97529
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97529