scsi: qla2xxx: Fix BSG job leak on validate flash image error path

Summary

CVECVE-2026-89862
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-16 11:16:54 UTC
Updated2026-09-16 11:16:54 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix BSG job leak on validate flash image error path qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally, telling the FC BSG transport (fc_bsg_host_dispatch()) that the driver owns and will complete the request. But bsg_job_done() is guarded by "if (!rval)", so on the error path (rval == -EINVAL) neither the driver nor the transport completes the job. The request dangles until it times out, leaking block layer resources. Commit c2c68225b145 ("scsi: qla2xxx: Fix bsg_done() causing double free") added the "if (!rval)" guard to a batch of BSG handlers. That is correct for handlers that also return the error code (the transport then completes the job once via fail_host_msg), but this function returns QLA_SUCCESS unconditionally, so the guard turned a correct single completion into a leak. Always call bsg_job_done(): bsg_reply->result is DID_OK and the error is reported in vendor_rsp[0], and since the function returns 0 the transport will not complete the job a second time.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0 e25241f9fa01fb0c088381a156d84a725b71c1ef git Not specified
CNA Linux Linux affected c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0 0fb52cc632464b0cd07f970341330466d772efe1 git Not specified
CNA Linux Linux affected 057a5bdc481e58ab853117254867ffb22caf9f6e git Not specified
CNA Linux Linux affected f2bbb4db0e4a4fbd5e649c0b5d8733f61da24720 git Not specified
CNA Linux Linux affected 27ac9679c43a09e54e2d9aae9980ada045b428e0 git Not specified
CNA Linux Linux affected 74e7458537cd9349cf019862e51491f670871707 git Not specified
CNA Linux Linux affected 871f6236da96c4a9712b8a29d7f555f767a47e95 git Not specified
CNA Linux Linux affected 31f33b856d2324d86bcaef295f4d210477a1c018 git Not specified
CNA Linux Linux affected 708003e1bc857dd014d4c44278d7d77c26f91b1c git Not specified
CNA Linux Linux affected 5.10.251 5.11 semver Not specified
CNA Linux Linux affected 5.15.201 5.16 semver Not specified
CNA Linux Linux affected 6.1.164 6.2 semver Not specified
CNA Linux Linux affected 6.6.127 6.7 semver Not specified
CNA Linux Linux affected 6.12.74 6.13 semver Not specified
CNA Linux Linux affected 6.18.13 6.19 semver Not specified
CNA Linux Linux affected 6.19.3 6.20 semver Not specified
CNA Linux Linux affected 7.0 Not specified
CNA Linux Linux unaffected 7.0 semver Not specified
CNA Linux Linux unaffected 7.2.5 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0fb52cc632464b0cd07f970341330466d772efe1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e25241f9fa01fb0c088381a156d84a725b71c1ef 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report