scsi: qla2xxx: Serialize flash version read in reset handler

Summary

CVECVE-2026-89855
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-16 11:16:53 UTC
Updated2026-09-16 11:16:53 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in reset handler The "update cache versions without reset" sysfs reset operation (0x20261) calls get_flash_version(), which reads hardware flash registers, without holding ha->optrom_mutex. The VPD update path serializes the same call under optrom_mutex, so this reset path can interleave its flash register accesses with a concurrent VPD or optrom flash operation and corrupt the reads. Hold ha->optrom_mutex across the get_flash_version() call to match the VPD update path.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 8c2cf7d4e387d003259488522523807f25576427 f1fc052f2a5890ea6dba80d50254dd6258b13386 git Not specified
CNA Linux Linux affected 8c2cf7d4e387d003259488522523807f25576427 31bf2714abbb0aa5a8a03d15038f8920e1c74b21 git Not specified
CNA Linux Linux affected 8c2cf7d4e387d003259488522523807f25576427 ae979c549cba684e67b6c047140f3a8d2439b298 git Not specified
CNA Linux Linux affected 8c2cf7d4e387d003259488522523807f25576427 9cef42a073a0bdeee7fb1b47221cda222d330d2a git Not specified
CNA Linux Linux affected 8c2cf7d4e387d003259488522523807f25576427 75460967619eda720c9a03767729157ffd171d8c git Not specified
CNA Linux Linux affected 8c2cf7d4e387d003259488522523807f25576427 8d116137119371349fb09685fe05413d8fc92efe git Not specified
CNA Linux Linux affected 8c2cf7d4e387d003259488522523807f25576427 33735490789e5417851752974c0b1d23125559cd git Not specified
CNA Linux Linux affected 8c2cf7d4e387d003259488522523807f25576427 f606ed93de0c4f1e7e3618779e9fad731455314a git Not specified
CNA Linux Linux affected 3.12 Not specified
CNA Linux Linux unaffected 3.12 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.51 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.5 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/31bf2714abbb0aa5a8a03d15038f8920e1c74b21 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ae979c549cba684e67b6c047140f3a8d2439b298 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/33735490789e5417851752974c0b1d23125559cd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/75460967619eda720c9a03767729157ffd171d8c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f1fc052f2a5890ea6dba80d50254dd6258b13386 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8d116137119371349fb09685fe05413d8fc92efe 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9cef42a073a0bdeee7fb1b47221cda222d330d2a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f606ed93de0c4f1e7e3618779e9fad731455314a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report