Impact
The vulnerability originates in the qla2xxx SCSI driver of the Linux kernel. A missing free of a spare memory block in the module’s error handling path allows the kernel to leave objects in a slab cache at module unload, causing a crash via kmem_cache_destroy. The immediate effect is a kernel panic or system crash, resulting in denial of service. The weakness is a memory management flaw (CWE-772).
Affected Systems
Affected systems are any Linux systems running the qla2xxx SCSI driver before the patch was applied. The vendor is Linux; the product is the Linux kernel. The example refers to kernel 5.14.0-284.11.1.el9_2.x86_64, so older kernels with the qla2xxx driver are potentially impacted.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. The EPSS score of <1% means that the exploitation likelihood is currently very low. The vulnerability is not listed in the CISA KEV catalog. Attack is likely local and requires the ability to load and unload the qla2xxx driver, which a system administrator or local attacker can perform, potentially leading to a kernel panic.
OpenCVE Enrichment
Debian DLA
Debian DSA