← All Advisories

CVE-2026-97537

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97537

Key Details

CVECVE-2026-97537
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking

qla25xx_free_req_que() and qla25xx_free_rsp_que() have two pre-existing

bugs exposed on the error path of qla25xx_create_{req,rsp}_que():

1. When dma_alloc_coherent() fails during queue creation, the error

path calls the free function with req->ring / rsp->ring still NULL

(from kzalloc). The unconditional dma_free_coherent() with a NULL

cpu_addr is undefined behavior and can panic.

2. The free functions clear req_qid_map / rsp_qid_map under vport_lock,

but the create functions protect the same bitmaps with mq_lock.

This provides no mutual exclusion. Additionally, the create error

path clears the bit and releases mq_lock before calling the free

function, creating a window where another thread can allocate the

same que_id and have its ha->req_q_map entry clobbered by the

subsequent lockless NULL assignment in the free function.

Fix by:

- Guarding dma_free_coherent() with a NULL check on the ring pointer.

- Using mq_lock (the lock held by all creators) in the free functions

to atomically NULL the map entry and clear the bitmap bit.

- Removing the now-redundant clear_bit blocks from the create error

paths since the free functions handle it atomically. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97537
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97537