In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Wait for io return on terminate rport System crash due to use after free. Current code allows terminate_rport_io to exit before making sure all IOs has returned. For FCP-2 device, IO's can hang on in HW because driver has not tear down the session in FW at first sign of cable pull. When dev_loss_tmo timer pops, terminate_rport_io is called and upper layer is about to free various resources. Terminate_rport_io trigger qla to do the final cleanup, but the cleanup might not be fast enough where it leave qla still holding on to the same resource. Wait for IO's to return to upper layer before resources are freed.
Update Linux/Linux to 8a55556cd7e0220486163b1285ce11a8be2ce5fa if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanscsi: qla2xxx: Wait for io return on terminate rport affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Wait for io return on terminate rport System crash due to use after free. Current code allows terminate_rport_io to exit before making sure all IOs has returned. For FCP-2 device, IO's can hang on in HW because driver has not tear down the session in FW at first sign of cable pull. When dev_loss_tmo timer pops, terminate_rport_io is called and upper layer is about to free various resources. Terminate_rport_io trigger qla to do the final cleanup, but the cleanup might not be fast enough where it leave qla still holding on to the same resource. Wait for IO's to return to upper layer before resources are freed.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Wait for io return on terminate rport System crash due to use after free. Current code allows terminate_rport_io to exit before making sure all IOs has returned. For FCP-2 device, IO's can hang on in HW because driver has not tear down the session in FW at first sign of cable pull. When dev_loss_tmo timer pops, terminate_rport_io is called and upper layer is about to free various resources. Terminate_rport_io trigger qla to do the final cleanup, but the cleanup might not be fast enough where it leave qla still holding on to the same resource. Wait for IO's to return to upper layer before resources are freed.
Update Linux/Linux to 8a55556cd7e0220486163b1285ce11a8be2ce5fa if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanscsi: qla2xxx: Wait for io return on terminate rport affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Wait for io return on terminate rport System crash due to use after free. Current code allows terminate_rport_io to exit before making sure all IOs has returned. For FCP-2 device, IO's can hang on in HW because driver has not tear down the session in FW at first sign of cable pull. When dev_loss_tmo timer pops, terminate_rport_io is called and upper layer is about to free various resources. Terminate_rport_io trigger qla to do the final cleanup, but the cleanup might not be fast enough where it leave qla still holding on to the same resource. Wait for IO's to return to upper layer before resources are freed.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric |
|---|
| >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <8a55556cd7e0220486163b1285ce11a8be2ce5fa || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <4647d2e88918a078359d1532d90c417a38542c9e || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <d25fded78d88e1515439b3ba581684d683e0b6ab || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <a9fe97fb7b4ee21bffb76f2acb05769bad27ae70 || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <079c8264ed9fea8cbcac01ad29040f901cbc3692 || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <90770dad1eb30967ebd8d37d82830bcf270b3293 || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <5bcdaafd92be6035ddc77fa76650cf9dd5b864c4 || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <fc0cba0c7be8261a1625098bd1d695077ec621c9 |
| 8a55556cd7e0220486163b1285ce11a8be2ce5fa, 4647d2e88918a078359d1532d90c417a38542c9e, d25fded78d88e1515439b3ba581684d683e0b6ab, a9fe97fb7b4ee21bffb76f2acb05769bad27ae70, 079c8264ed9fea8cbcac01ad29040f901cbc3692, 90770dad1eb30967ebd8d37d82830bcf270b3293, 5bcdaafd92be6035ddc77fa76650cf9dd5b864c4, fc0cba0c7be8261a1625098bd1d695077ec621c9 |
| Linux/Linuxgeneric | 2.6.34 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Linux/Linuxgeneric |
|---|
| >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <8a55556cd7e0220486163b1285ce11a8be2ce5fa || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <4647d2e88918a078359d1532d90c417a38542c9e || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <d25fded78d88e1515439b3ba581684d683e0b6ab || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <a9fe97fb7b4ee21bffb76f2acb05769bad27ae70 || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <079c8264ed9fea8cbcac01ad29040f901cbc3692 || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <90770dad1eb30967ebd8d37d82830bcf270b3293 || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <5bcdaafd92be6035ddc77fa76650cf9dd5b864c4 || >=715848ca6fffeb6362a50887d9c26245bd5dfba9 <fc0cba0c7be8261a1625098bd1d695077ec621c9 |
| 8a55556cd7e0220486163b1285ce11a8be2ce5fa, 4647d2e88918a078359d1532d90c417a38542c9e, d25fded78d88e1515439b3ba581684d683e0b6ab, a9fe97fb7b4ee21bffb76f2acb05769bad27ae70, 079c8264ed9fea8cbcac01ad29040f901cbc3692, 90770dad1eb30967ebd8d37d82830bcf270b3293, 5bcdaafd92be6035ddc77fa76650cf9dd5b864c4, fc0cba0c7be8261a1625098bd1d695077ec621c9 |
| Linux/Linuxgeneric | 2.6.34 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard