---
id: CVE-2026-89857
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject

  qla_nvme_ls_reject_iocb() allocates from and advances the request ring
  through __qla2x00_alloc_iocbs() (whic…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject

  qla_nvme_ls_reject_iocb() allocates from and advances the request ring
  through __qla2x00_alloc_iocbs() (whic…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 875386b98857822b77ac7f95bdf367b70af5b78c <
    7eb618877503edbf17aa65e357a81bda1fc8f163
  - >-
    Linux >= 875386b98857822b77ac7f95bdf367b70af5b78c <
    b3a362466db6b8ec47cc537ac641ac197fa69b5d
  - >-
    Linux >= 875386b98857822b77ac7f95bdf367b70af5b78c <
    11834e5773e20fd3742d7eb900876e66b9e7d029
  - >-
    Linux >= 875386b98857822b77ac7f95bdf367b70af5b78c <
    b02ff132017b28222187ebcf95ce7f4cb576cd36
  - >-
    Linux >= 875386b98857822b77ac7f95bdf367b70af5b78c <
    f743488e4a203049f27ec5d8cd0caccc483af01e
  - Linux 6.6
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:13.657'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89857'
references:
  - url: 'https://git.kernel.org/stable/c/11834e5773e20fd3742d7eb900876e66b9e7d029'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7eb618877503edbf17aa65e357a81bda1fc8f163'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b02ff132017b28222187ebcf95ce7f4cb576cd36'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b3a362466db6b8ec47cc537ac641ac197fa69b5d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f743488e4a203049f27ec5d8cd0caccc483af01e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.992Z'
epss: 0.00671
epssPercentile: 0.50035
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject

qla_nvme_ls_reject_iocb() allocates from and advances the request ring
through __qla2x00_alloc_iocbs() (which assumes the hardware_lock is
held) and qla2x00_start_iocbs() (which advances the ring and rings the
request-in doorbell), but takes no lock itself. Two of its callers
invoke it without the producer lock held:

 - qla_nvme_xmt_ls_rsp(), the NVMe-FC .xmt_ls_rsp transport callback, on
   its error path, and

 - qla2xxx_process_purls_pkt(), run from the purex work/DPC context.

Both use ha->base_qpair, whose qp_lock_ptr is hardware_lock, so they can
run concurrently with normal I/O submission on the base ring and corrupt
the ring producer state, leading to duplicated or dropped commands. The
third caller, qla2xxx_process_purls_iocb(), runs inside
qla24xx_process_response_queue() with the qpair lock already held and is
safe; that is also why the lock cannot be taken inside the helper itself
(it would recursively re-acquire hardware_lock on the response path).

Take qp_lock_ptr around the two unlocked callers and document the helper
as caller-locked. Both run in process context, so spin_lock_irqsave() is
used and nothing in the locked region sleeps.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
