Home

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash when I/O abort times out While performing CPU hotplug, a crash with the following stack was seen: Call Trace: qla24xx_process_response_queue+0x42a/0x970 [qla2xxx] qla2x00_start_nvme_mq+0x3a2/0x4b0 [qla2xxx] qla_nvme_post_cmd+0x166/0x240 [qla2xxx] nvme_fc_start_fcp_op.part.0+0x119/0x2e0 [nvme_fc] blk_mq_dispatch_rq_list+0x17b/0x610 __blk_mq_sched_dispatch_requests+0xb0/0x140 blk_mq_sched_dispatch_requests+0x30/0x60 __blk_mq_run_hw_queue+0x35/0x90 __blk_mq_delay_run_hw_queue+0x161/0x180 blk_execute_rq+0xbe/0x160 __nvme_submit_sync_cmd+0x16f/0x220 [nvme_core] nvmf_connect_admin_queue+0x11a/0x170 [nvme_fabrics] nvme_fc_create_association.cold+0x50/0x3dc [nvme_fc] nvme_fc_connect_ctrl_work+0x19/0x30 [nvme_fc] process_one_work+0x1e8/0x3c0 On abort timeout, completion was called without checking if the I/O was already completed. Verify that I/O and abort request are indeed outstanding before attempting completion.

PUBLISHED Reserved 2025-10-04 | Published 2025-10-04 | Updated 2025-10-04 | Assigner Linux

Product status

Default status
unaffected

71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 before d3871af13aa03fbbe7fbb812eaf140501229a72e
affected

71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 before cb4dff498468b62e8c520568559b3a9007e104d7
affected

71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 before 05382ed9142cf8a8a3fb662224477eecc415778b
affected

71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 before 68ad83188d782b2ecef2e41ac245d27e0710fe8e
affected

457173c8b43ecd3ac48c8ace8d4437a50f7ad77b
affected

b7abcc7df5e131c0b4bf89cb2411c5301ee83d26
affected

Default status
affected

5.5
affected

Any version before 5.5
unaffected

5.15.86
unaffected

6.0.16
unaffected

6.1.2
unaffected

6.2
unaffected

References

git.kernel.org/...c/d3871af13aa03fbbe7fbb812eaf140501229a72e

git.kernel.org/...c/cb4dff498468b62e8c520568559b3a9007e104d7

git.kernel.org/...c/05382ed9142cf8a8a3fb662224477eecc415778b

git.kernel.org/...c/68ad83188d782b2ecef2e41ac245d27e0710fe8e

cve.org (CVE-2022-50493)

nvd.nist.gov (CVE-2022-50493)

Download JSON