GHSA-vhpc-fmr8-vgccunknown

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound i2c-...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Bound i2c->length in I2C bsg handlers

struct qla_i2c_access carries a 16-bit length field alongside a fixed 64-byte buffer:

struct qla_i2c_access {
	uint16_t device, offset, option, length;
	uint8_t  buffer[0x40];
} __packed;

qla2x00_write_i2c() and qla2x00_read_i2c() use the user-supplied i2c->length without any bounds check. i2c is overlaid on a 256-byte on-stack buffer and sfp is a 256-byte DMA-pool buffer, so a length up to 65535 overruns both:

  • write: memcpy(sfp, i2c->buffer, i2c->length) over-reads the stack and over-writes the sfp heap buffer, and qla2x00_write_sfp() then DMAs i2c->length bytes out of the 256-byte buffer.
  • read: qla2x00_read_sfp() DMAs i2c->length bytes into the 256-byte sfp, then memcpy(i2c->buffer, sfp, i2c->length) overflows the 64-byte buffer inside the on-stack array.

A caller holding CAP_SYS_RAWIO can use this to corrupt the heap and the kernel stack. Reject requests whose length exceeds the buffer before any copy or DMA transfer in both handlers.

🔗 References (10)