CVE-2026-43414

Aliases:UBUNTU-CVE-2026-43414DEBIAN-CVE-2026-43414CGA-22qw-5947-wp4hCGA-2m34-v72f-fw96CGA-2vfj-vq5x-93jpCGA-4629-m565-j55qCGA-7wpr-c7xx-88xgCGA-8973-pgg8-gf8pCGA-8qmc-97w2-c282CGA-c545-qvp6-8546CGA-gxfc-wpg9-9xr9CGA-hfvr-w3xf-3r79CGA-j5wp-p7p9-p9w9CGA-jrqf-fq83-7fgrCGA-pwq3-42fp-7h8fCGA-qv6h-7vjr-hph4CGA-rwm9-x8qm-h3m5CGA-w28w-w695-5wm8CGA-x284-5pmw-454hCGA-j23v-fjhx-66vpCGA-j2m6-5gvh-fc46CGA-6vf2-rfw8-j3mxCGA-8x85-p766-9vmpCGA-j9g2-5689-qxgcCGA-m3v5-j269-8c3jCGA-mw9f-g6xf-qhm3CGA-pvvv-wffh-9hqqCGA-q8c8-pqqw-grr2CGA-qpcq-j86c-3r4vCGA-rf74-x6hh-6fxrCGA-v6fh-ggrj-9vv7CGA-w4m6-c88r-2jvhCGA-xchm-hprc-m7v9
Analyzed
Published: 08 May 2026, 14:21
Last modified:05 Aug 2026, 12:27

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
0.38% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 May 2026, 14:21
Published
Vulnerability first disclosed
05 Aug 2026, 12:27
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is called by qla2x00_sp_release(), when kref_put() releases the first and the last reference. qla2x00_els_dcmd_sp_free() frees fcport by calling qla2x00_free_fcport(). Doing it one more time after kref_put() is a bad idea.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.38% Percentile: 32%

Techniques & Countermeasures

  • CWE-415Double Free

    The product calls free() twice on the same memory address.

Affected Systems

  • chainguardlinux-aws-6.12

    < 0

  • chainguardlinux-aws-6.18

    < 0

  • chainguardlinux-azure-6.12

    < 0

  • chainguardlinux-azure-6.18

    < 0

  • chainguardlinux-desktop-6.18

    all

  • chainguardlinux-desktop-6.18-bootc

    all

  • chainguardlinux-desktop-6.18-bootc-boot-installed

    all

  • chainguardlinux-desktop-6.18-headers

    all

  • chainguardlinux-desktop-6.18-modules

    all

  • chainguardlinux-firecracker-6.18

    all

  • chainguardlinux-gcp-6.12

    < 0

  • chainguardlinux-gcp-6.18

    < 0 | < 6.18.38-r2

  • chainguardlinux-gcp-6.18-bootc

    < 6.18.38-r2

  • chainguardlinux-gcp-6.18-bootc-boot-installed

    < 0

  • chainguardlinux-qemu-6.12

    < 0

  • chainguardlinux-qemu-6.18

    < 0 | < 6.18.38-r2

  • chainguardlinux-qemu-6.18-bootc

    < 6.18.38-r2

  • chainguardlinux-qemu-6.18-bootc-boot-installed

    < 0

  • chainguardlinux-qemu-melange

    < 0

  • chainguardlinux-vmware-6.12

    < 0

  • chainguardlinux-vmware-6.18

    < 0

  • debianlinux

    all | all | < 6.19.10-1

  • ubuntulinux

    all | < 4.4.0-283.317 | < 4.15.0-253.265 | < 5.4.0-233.253 | < 5.15.0-185.195 | < 6.8.0-134.134 | < 6.17.0-40.40

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | < 4.4.0-1156.162 | < 4.4.0-1194.209 | < 4.15.0-1194.207 | < 5.4.0-1161.172 | < 5.15.0-1111.118 | < 6.8.0-1060.63 | < 6.17.0-1019.19

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1111.118~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1161.172~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.17

    < 6.17.0-1019.19~24.04.1

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1060.63~22.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2132.138 | < 5.4.0-1161.172+fips1 | < 5.15.0-1111.118+fips1 | < 6.8.0-1060.63+fips1

  • ubuntulinux-aws-hwe

    all | < 4.15.0-1194.207~16.04.1

  • ubuntulinux-azure

    all | < 4.15.0-1205.220~14.04.1 | < 4.15.0-1204.219~16.04.1 | all | < 5.4.0-1166.172 | < 5.15.0-1116.125 | < 6.8.0-1063.71 | all

  • ubuntulinux-azure-4.15

    < 4.15.0-1204.219

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1116.125~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1166.172~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

Showing first 50 affected entries in server-rendered view.

References (46)