CVE-2026-90285

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path qla2x00_sysfs_read_vpd() called ha->isp_ops->read_optrom() a second time after releasing optrom_mutex. The repeated read is redundant and, unlike the first, runs without optrom_mutex held, exposing flash access to concurrent optrom operations. Drop the duplicate call.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Sep 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-17 17:17

Updated : 2026-09-17 17:17


NVD link : CVE-2026-90285

Mitre link : CVE-2026-90285

CVE.ORG link : CVE-2026-90285


JSON object : View

Products Affected

No product.

CWE

No CWE.