← All Advisories

CVE-2026-97535

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97535

Key Details

CVECVE-2026-97535
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size

The VP control IOCB selects its target virtual port by setting one bit

in vp_idx_map, a fixed 16-byte (128-bit) array in both

vp_ctrl_entry_24xx and vp_ctrl_entry_24xx_ext. qla25xx_ctrlvp_iocb()

computes map = (vp_index - 1) / 8 and writes vce->vp_idx_map[map]

without checking that map stays within the array.

max_npiv_vports is taken from firmware and only sanitized to a

MIN_MULTI_ID_FABRIC-aligned boundary, so it can legitimately be 191 or

255, and qla24xx_control_vp() only rejects vp_index >= max_npiv_vports.

A vp_index above 128 therefore yields map >= 16 and an out-of-bounds

write of up to 16 bytes past vp_idx_map, corrupting the trailing IOCB

fields (or the adjacent request-ring slot on the 64-byte layout).

Reject a vp_index that cannot be represented in the IOCB bitmap in

qla24xx_control_vp(), and add a defensive ARRAY_SIZE() guard in

qla25xx_ctrlvp_iocb() before the write. Adapters that report the usual

63 or 127 NPIV vports are unaffected. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97535
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97535