Impact
The qla2xxx NVMe driver in the Linux kernel incorrectly triggers a doorbell write and queues an IOCB even when the firmware has not started. This behavior leads to the kernel performing a hardware register write during a reset or error‑handling window that the firmware cannot process, which can cause kernel instability or a system crash. The flaw allows a firmware not yet ready to consume a command to receive an unsolicited request, potentially corrupting memory or causing a denial of service at the kernel level.
Affected Systems
Linux kernel implementations that include the qla2xxx SCSI driver are impacted. Versions prior to the fix (identified by the provided commit hash references) are vulnerable; the fix applies to all kernel releases that incorporate the patch.
Risk and Exploitability
The EPSS score indicates an exploitation probability of less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The absence of a public CVSS score combined with the low EPSS suggests a modest risk level under typical conditions. The attack vector is expected to be local: any user with sufficient privilege to interact with an NVMe device connected via the qla2xxx driver could trigger the fault. Because the flaw results in a kernel panic rather than remote code execution, the overall risk remains in the deny‑of‑service category rather than privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA